Vulnerability Description
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.
CVSS Score
MEDIUM
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk | cpr9 |
| Rockwellautomation | Rslogix 5000 | 17 |
Related Weaknesses (CWE)
References
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdfUS Government Resource
- http://rockwellautomation.custhelp.com/app/answers/detail/a_id/469937
- http://www.us-cert.gov/control_systems/pdf/ICSA-12-088-01.pdfUS Government Resource
FAQ
What is CVE-2012-0222?
CVE-2012-0222 is a vulnerability with a CVSS score of 5.0 (MEDIUM). The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-...
How severe is CVE-2012-0222?
CVE-2012-0222 has been rated MEDIUM with a CVSS base score of 5.0/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2012-0222?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk, Rockwellautomation Rslogix 5000.