CVE-2011-3489

Severity CVSS v4.0:
Pending analysis
Type:
CWE-119 Buffer Errors
Publication date:
16/09/2011
Last modified:
11/04/2025

Description

RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related to improper handling of a 32-bit size field.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:rslogix:*:*:*:*:*:*:*:* 19 (including)