Juniper Networks
Solutions
Products & Services
Company
Partners
Support
Education

Signature Detail

Security Intelligence Center
Signatures
Print

This site is deprecated. Please CLICK HERE for latest updates

Short Name

APP:MISC:RKWL-RRDATA-OF

Severity

Major

Recommended

Yes

Recommended Action

Drop

Category

APP

Keywords

Rockwell Automation RSLinx Classic Forward Open Electronic Key Stack Buffer Overflow

Release Date

2019/03/13

Update Number

3151

Supported Platforms

srx-17.3+, srx-branch-17.4+, vsrx-15.1+, vsrx3bsd-18.2+

APP: Rockwell Automation RSLinx Classic Forward Open Electronic Key Stack Buffer Overflow


This signature detects attempts to exploit a known vulnerability against Rockwell Automation RSLinx Classic. The vulnerability is due to a flaw in the module that processes CIP SendRRData messages with overly large size field within the Electronic Key segment in the Connection Path. A remote unauthenticated attacker can exploit this vulnerability by sending a specially crafted packet to the vulnerable service. Successful exploitation could lead to buffer overflow or crash of the vulnerable application.

Extended Description

A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed size buffer, allowing an attacker to exploit a stack-based buffer overflow condition.

Affected Products

  • Rockwellautomation rslinx 4.10.00

References

  • CVE: CVE-2019-6553

Site Map
RSS Feeds
Careers
Accessibility
Feedback
Privacy Policy
Legal Notices
Copyright © 1999-2010 Juniper Networks, Inc. All rights reserved.
Help
|
My Account
|
Log Out