5
CVSSv2

CVE-2011-3489

Published: 16/09/2011 Updated: 29/08/2017
CVSS v2 Base Score: 5 | Impact Score: 2.9 | Exploitability Score: 10
VMScore: 505
Vector: AV:N/AC:L/Au:N/C:N/I:N/A:P

Vulnerability Summary

RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and previous versions allows remote malicious users to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related to improper handling of a 32-bit size field.

Vulnerability Trend

Vulnerable Product Search on Vulmon Subscribe to Product

rockwellautomation rslogix

Exploits

####################################################################### Luigi Auriemma Application: Rockwell RSLogix wwwrockwellautomationcom/rockwellsoftware/design/rslogix5000/ Versions: <= 19 (RsvcHostexe 230023) Platforms: Windows Bug: Denial of Service Exploitation: ...