← Vulnerability feed

Vulnerability record · CVE-2012-6438 · published 24 January 2013

CVE-2012-6438: Rockwellautomation controllogix controllers memory buffer overflow vulnerability

Rockwellautomation · Controllogix Controllers

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of availability and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

7.5 CVSS 3.1 High EPSS 27% · top 2.0% CWE-119 · Memory buffer overflow
7.5CVSS 3.1 base score, v2 7.8
27%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of availability and a disruption in communications with other connected devices. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6438 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-6437Rockwellautomation controllogix controllers improper authentication vulnerabilityThe device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…EPSS 7.8%8.5CVE-2012-6439Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 23%7.5CVE-2012-6435Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 33%7.5CVE-2012-6436Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%5.0CVE-2012-6441Rockwell Automation EtherNet/IP modules expose confidential data via crafted CIP packetA specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to ex…EPSS 57%analysed4.8CVE-2012-6440Rockwellautomation controllogix controllers improper authentication vulnerabilityThe Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vuln…EPSS 9.3%8.8CVE-2026-8452Citrix NetScaler ADC and Gateway memory buffer overflow causes DoSCVE-2026-8452 is a memory buffer overflow (CWE-119) in Citrix NetScaler ADC and NetScaler Gateway that leads to unpredictable or erroneous behavior a…KEVEPSS 1.0%analysed8.8CVE-2009-3459Adobe Reader and Acrobat heap buffer overflow via crafted PDFAdobe Reader and Acrobat 7.x before 7.1.4, 8.x before 8.1.7, and 9.x before 9.2 contain a heap-based buffer overflow (CWE-122) triggered by a crafted…KEVEPSS 87%analysed

Source: NIST National Vulnerability Database (record CVE-2012-6438), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.