Back

CVE-2018-14829

CRITICAL

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition, which may allow the threat actor to remotely execute arbitrary code.

Published: Sep 20, 2018 Modified: Jun 17, 2026
CWE-121 CWE-119

CVSS Metrics

CVSSv3
Attack Vector: NETWORK Attack Complexity: LOW Privileges Required: NONE User Interaction: NONE Scope: UNCHANGED Confidentiality Impact: HIGH Integrity Impact: HIGH Availability Impact: HIGH

CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected Products (1)

Vendor Product Version
rockwellautomation rslinx *

GitHub Security Advisory GHSA-264m-mv26-f7f5

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a...

References (4)

Risk Scores

CVSS Score 9.8 / 10
EPSS Score 16.09%

Top 3% most likely to be exploited

Threat Score 44 / 100

Data Sources

NVD EPSS GitHub