Logic Error in Rockwell Automation RSLinx Enterprise Software
CVE-2013-2805
7.5HIGH
What is CVE-2013-2805?
The RSLinx Enterprise Software from Rockwell Automation experiences a logic error when it improperly processes input. Specifically, if the software receives a datagram with an oversized value in the 'Record Data Size' field, it leads to an out-of-bounds read access violation, resulting in a service crash. Recovery requires a manual reboot of the service. For further details and patches, check Rockwell Automation’s Security Advisory.
Affected Version(s)
RSLinx Enterprise Software CPR9
RSLinx Enterprise Software CPR9-SR1
RSLinx Enterprise Software CPR9-SR2