CVE-2018-19016 is a denial-of-service vulnerability affecting Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (and 1756-EWEBK) versions 5.001 and earlier, and CompactLogix 1768-EWEB version 2.005 and earlier. A remote attacker can exploit this by sending a specially crafted UDP packet to the SNMP service, causing the affected device to become unresponsive until restarted. This vulnerability has a CVSS score of 7.5 (HIGH), indicating a network-based attack with low complexity and high impact on availability, requiring no user interaction or privileges. There is currently no evidence of active exploitation, public exploit code, or significant community discussion surrounding this CVE.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 5.001CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:ethernet\/ip_web_server_module_1756-eweb:*:*:*:*:*:*:*:* | ||
<= 2.005CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:ethernet\/ip_web_server_module_1768-eweb:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Rockwell Automation EWEB SNMP Denial of Service
Feb 4, 2019Rockwell Automation EWEB SNMP Denial of Service
Feb 4, 2019Rockwell Automation EWEB SNMP Denial of Service
Feb 4, 2019