CVE-2018-14829
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
1Exploited in Wild
-Decision
Descriptions
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.
Rockwell Automation RSLinx Classic en versiones 4.00.01 y anteriores. Esta vulnerabilidad podría permitir que un actor de amenaza remoto envíe de forma intencional un paquete CIP mal formado al puerto 44818, lo que provoca que la aplicación deje de responder y se cierre inesperadamente. La vulnerabilidad también tiene potencial para explotar una condición de desbordamiento de búfer, lo que podría permitir que el actor de amenaza ejecutar código arbitrario de forma remota.
CVSS Scores
SSVC
- Decision:-
Timeline
- 2018-08-01 CVE Reserved
- 2018-09-20 CVE Published
- 2024-07-30 EPSS Updated
- 2024-09-16 CVE Updated
- 2024-09-16 First Exploit
- ---------- Exploited in Wild
- ---------- KEV Due Date
CWE
- CWE-119: Improper Restriction of Operations within the Bounds of a Memory Buffer
- CWE-121: Stack-based Buffer Overflow
CAPEC
References (2)
URL | Tag | Source |
---|---|---|
https://ics-cert.us-cert.gov/advisories/ICSA-18-263-02 | Third Party Advisory |
URL | Date | SRC |
---|---|---|
https://www.tenable.com/security/research/tra-2018-26 | 2024-09-16 |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Rslinx Search vendor "Rockwellautomation" for product "Rslinx" | <= 4.00.01 Search vendor "Rockwellautomation" for product "Rslinx" and version " <= 4.00.01" | classic |
Affected
|