CVE-2020-13573
Rockwell Automation RSLinx Classic vulnerability analysis and mitigation

Overview

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. The vulnerability, tracked as CVE-2020-13573, was discovered by Alexander Perez-Palma of Cisco Talos and allows an attacker to cause a denial of service condition by sending specially crafted network requests (Talos Report, SecurityWeek).

Technical details

The vulnerability occurs when sending a Register Session request followed by a Send Unit Data message where the Address Item Length is smaller than the data that follows. The issue stems from a lack of validation check comparing user input size against what the application can receive and process. When exploited, the resulting pointer points to unmapped memory and crashes when dereferenced. The vulnerability has been assigned a CVSS v3.0 base score of 7.5 (High) with vector: CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H and is classified as CWE-823 (Use of Out-of-range Pointer Offset) (Talos Report).

Impact

When successfully exploited, the vulnerability can cause a denial of service condition in the RSLinx component. While this would not typically impact the operation of the PLC directly, it would prevent administrators from applying new configurations and changes to the PLC and lose visibility into the PLC's operation (SecurityWeek).

Exploitability

The vulnerability can be exploited by an unauthenticated remote attacker by sending a sequence of malicious packets to trigger the denial of service condition. The attack requires no user interaction and has low attack complexity (Talos Report).

Mitigation and workarounds

According to Cisco Talos, the issue was resolved by Rockwell Automation in November 2020. The vendor acknowledged the issue was resolved on January 5, 2021 (Talos Report).

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation RSLinx Classic vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2020-12001CRITICAL9.8
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:factorytalk_linx
NoYesJun 15, 2020
CVE-2020-11999HIGH8.1
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx_classic
NoYesJun 15, 2020
CVE-2020-13573HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:rslinx
NoYesJan 07, 2021
CVE-2020-12005HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:factorytalk_linx
NoYesJun 15, 2020
CVE-2020-12003HIGH7.5
  • Rockwell Automation RSLinx Classic logoRockwell Automation RSLinx Classic
  • cpe:2.3:a:rockwellautomation:factorytalk_linx
NoYesJun 15, 2020

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management