CVE-2013-2805 is a logic error vulnerability affecting Rockwell Automation RSLinx Enterprise software versions CPR9 through CPR9-SR6. An attacker can exploit this by sending a malformed UDP datagram to port 4444, specifically manipulating the "Record Data Size" field. This triggers an out-of-bounds read, causing the LogReceiver.exe service to crash, leading to a denial of service that requires a manual reboot to restore. Rated with a CVSS score of 7.5 (HIGH), it is a network-exploitable vulnerability with low attack complexity and no user interaction required, resulting in high availability impact. There is no evidence of active exploitation, public exploit code (Metasploit, Nuclei, ExploitDB), or significant community discussion or media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
5.10.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx_enterprise:5.10.00:*:*:*:*:*:*:* | ||
5.10.01CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx_enterprise:5.10.01:*:*:*:*:*:*:* | ||
5.20.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx_enterprise:5.20.00:*:*:*:*:*:*:* | ||
5.21.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx_enterprise:5.21.00:*:*:*:*:*:*:* | ||
5.30.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx_enterprise:5.30.00:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.