← Vulnerability feed

Vulnerability record · CVE-2012-6435 · published 24 January 2013

CVE-2012-6435: Rockwellautomation controllogix controllers improper access control vulnerability

Rockwellautomation · Controllogix Controllers

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

7.5 CVSS 3.1 High EPSS 33% · top 1.7% CWE-284 · Improper access controlCWE-399 · CWE-399
7.5CVSS 3.1 base score, v2 7.8
33%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6435 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-6437Rockwellautomation controllogix controllers improper authentication vulnerabilityThe device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…EPSS 7.8%8.5CVE-2012-6439Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 23%7.5CVE-2012-6436Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%7.5CVE-2012-6438Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%5.0CVE-2012-6441Rockwell Automation EtherNet/IP modules expose confidential data via crafted CIP packetA specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to ex…EPSS 57%analysed4.8CVE-2012-6440Rockwellautomation controllogix controllers improper authentication vulnerabilityThe Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vuln…EPSS 9.3%7.8CVE-2026-81963Windows Update Stack link-following privilege escalationWindows Update Stack resolves links improperly before accessing files, a link-following flaw (CWE-59) compounded by improper access control (CWE-284)…KEVEPSS 0.39%analysed10.0CVE-2026-21962Oracle HTTP Server and WebLogic Proxy Plug-in improper access controlOracle HTTP Server and the WebLogic Server Proxy Plug-in (for Apache HTTP Server and IIS) contain an improper access control flaw (CWE-284) in suppor…KEVEPSS 71%analysed

Source: NIST National Vulnerability Database (record CVE-2012-6435), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.