目标达成 感谢每一位支持者 — 我们达成了 100% 目标!

目标: 1000 元 · 已筹: 1336

100%

CVE-2013-2807— Rockwell Automation RSLinx Enterprise 缓冲区错误漏洞

AI 预测 6.5 利用难度: 中等 EPSS 3.85% · P89
获取后续新漏洞提醒登录后订阅

一、 漏洞 CVE-2013-2807 基础信息

漏洞信息

对漏洞内容有疑问?看看神龙的深度分析是否有帮助!
查看神龙十问 ↗

尽管我们使用了先进的大模型技术,但其输出仍可能包含不准确或过时的信息。神龙努力确保数据的准确性,但请您根据实际情况进行核实和判断。

Vulnerability Title
N/A
来源: CVE Program / CVE List V5
Vulnerability Description
Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. By sending a datagram to the service over Port 4444/UDP with the “Record Data Size” field modified to a specifically oversized value, the service will calculate an undersized value for the “Total Record Size” that will cause an out-of-bounds read access violation that leads to a service crash. The service can be recovered with a manual reboot. The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation Security Advisory link (login is required): https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599
来源: CVE Program / CVE List V5
CVSS Information
N/A
来源: CVE Program / CVE List V5
Vulnerability Type
整数溢出或超界折返
来源: CVE Program / CVE List V5
Vulnerability Title
Rockwell Automation RSLinx Enterprise 缓冲区错误漏洞
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Description
Rockwell Automation RSLinx Enterprise是美国罗克韦尔(Rockwell Automation)公司的一套通讯管理软件。该软件可为Allen-Bradley(A-B)的可编程控制器、各种Rockwell软件、A-B应用软件建立起通讯联系。 Rockwell Automation RSLinx Enterprise中存在缓冲区错误漏洞,该漏洞源于程序对用户提交的数据没有进行正确的边界检查。攻击者可利用该漏洞导致服务崩溃。以下产品及版本受到影响:Rockwell Automa
来源: 中国国家信息安全漏洞库 CNNVD
CVSS Information
N/A
来源: 中国国家信息安全漏洞库 CNNVD
Vulnerability Type
N/A
来源: 中国国家信息安全漏洞库 CNNVD

受影响产品

厂商产品影响版本CPE订阅
Rockwell AutomationRSLinx Enterprise Software CPR9 -

二、漏洞 CVE-2013-2807 的公开POC

#POC 描述源链接神龙链接
AI 生成 POC高级

未找到公开 POC。

登录以生成 AI POC

三、漏洞 CVE-2013-2807 的情报信息

登录查看更多情报信息。

CVE-2013-2807 其他参考 (1)

同批安全公告 · Rockwell Automation · 2019-03-26 · 共 4 条

CVE-2013-2806Rockwell Automation RSLinx Enterprise 输入验证错误漏洞
CVE-2013-2805Rockwell Automation RSLinx Enterprise 缓冲区错误漏洞
CVE-2010-5305Rockwell Automation PLC-5和SLC 5/0x控制器访问控制错误漏洞

IV. Related Vulnerabilities

V. Comments for CVE-2013-2807

暂无评论


发表评论