VORANT. Threat Intelligence Sign in Get the full feed

Rockwell RSLinx buffer overflow enables remote code execution

high vulnerability manufacturingenergyinfrastructure

A stack-based buffer overflow in Rockwell Automation RSLinx Classic versions 4.50.00 and earlier allows remote code execution and denial of service against industrial control systems.

CISA has published an advisory for CVE-2020-13573, a stack-based buffer overflow vulnerability in Rockwell Automation's RSLinx Classic software. The flaw affects all versions up to and including 4.50.00 and can be exploited remotely to execute arbitrary code or cause denial of service conditions where the application becomes unresponsive and fails to recover automatically.

The vulnerability impacts critical infrastructure sectors including critical manufacturing, energy, food and agriculture, and water/wastewater systems worldwide. Rockwell Automation has released version 4.60.00 to address the issue and provides patch BF31213 for organizations unable to upgrade immediately.

No active exploitation has been reported to CISA at the time of publication. The vendor recommends implementing network segmentation, minimizing internet exposure of control systems, and using secure remote access methods as additional defensive measures.

Mentioned in this report

Vulnerabilities CVE-2020-13573

Source reporting: https://www.cisa.gov/news-events/ics-advisories/icsa-26-167-02

This is the public brief

Subscribers see the full picture: extracted IOCs, ready-to-deploy detections (Sigma, Splunk, KQL, Elastic, YARA, Suricata), the entity graph, TAXII 2.1 feed and real-time alerts matched to your sectors.

Start free