CVE-2018-14829 affects Rockwell Automation RSLinx Classic versions 4.00.01 and prior, allowing a remote attacker to send a malformed CIP packet to port 44818. This can cause a denial-of-service by crashing the application, or potentially enable remote arbitrary code execution through a buffer overflow. With a CVSS score of 9.8 (Critical), it has a high impact on confidentiality, integrity, and availability, requiring no user interaction or complex attack conditions. While no public exploit code is readily available (Metasploit, Nuclei, ExploitDB), it has garnered significant community discussion and media coverage, indicating awareness of its severity despite not being listed in CISA's KEV catalog.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 4.00.01CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:rslinx:*:*:*:*:classic:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.3 Bluesky, 0.3 Mastodon, and 2.4 GitHub mentions.
The average CVE in this peer group has 0.3 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
[R1] RSLinx Classic Buffer Overflows
Sep 20, 2018[R1] RSLinx Classic Buffer Overflows
Sep 20, 2018RSLinx Classic Buffer Overflows
Sep 20, 2018[R1] RSLinx Classic Buffer Overflows
Sep 20, 2018