CVE-2011-3489 describes a denial-of-service vulnerability in Rockwell RSLogix 19 and earlier, specifically within the RnaUtility.dll component of RsvcHost.exe. A remote attacker can crash the affected system by sending a specially crafted rna packet with a long string to TCP port 4446, triggering either a "memset zero overflow" or an out-of-bounds read due to improper handling of a 32-bit size field. This vulnerability has a CVSS score of 5.0, indicating a medium severity with network access, low attack complexity, no authentication required, and a partial impact on availability. While there is no evidence of active exploitation, a public exploit (EDB-17843) exists, and there is minimal community discussion or media coverage surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 19CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslogix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:L/Au:N/C:N/I:N/A:P
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.0 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.