← Vulnerability feed

Vulnerability record · CVE-2012-6441 · published 24 January 2013

CVE-2012-6441: Rockwell Automation EtherNet/IP modules expose confidential data via crafted CIP packet

Rockwellautomation · Controllogix Controllers

A specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to expose confidential information. The flaw affects a broad range of ControlLogix, CompactLogix, GuardLogix, SoftLogix, FLEXLogix, FLEX I/O and MicroLogix products, so unpatched industrial control networks carry a confidentiality risk.

5.0 CVSS 2.0 Medium EPSS 57% · top 1.0% CWE-200 · Information exposure
5.0CVSS 2.0 base score
57%EPSS exploitation probability, 30 days
NoNot in CISA KEV
17Affected product versions listed by NVD
6References
16 Jun 2026Last modified by NVD

Description

An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

AV:N/AC:L/Au:N/C:P/I:N/A:N

Automated analysis

Generated by VULONE's analysis model from the NVD record, CISA KEV and EPSS data on 19 September 2026. Confidence: medium.

high priorityThe flaw is remotely reachable without authentication on internet-exposed ICS ports and has a very high EPSS score, though it only causes confidentiality loss and has no confirmed exploit or KEV listing.

What it is

A specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to expose confidential information. The flaw affects a broad range of ControlLogix, CompactLogix, GuardLogix, SoftLogix, FLEXLogix, FLEX I/O and MicroLogix products, so unpatched industrial control networks carry a confidentiality risk.

Impact

An attacker gains read access to confidential information held or passed by the affected device; integrity and availability are not affected per the CVSS vector. The exposure is limited to confidentiality loss, but on ICS equipment that data may include sensitive process or configuration details.

Attack surface

Reachable over the network via CIP traffic to TCP/UDP ports 2222 and 44818; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can send packets to those ports on an exposed module can attempt the attack.

Exploitation

Not listed in CISA KEV and no ransomware associations are documented; EPSS is high at roughly 0.57 (99th percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.

What to do

  • Apply the Rockwell Automation fixes referenced in advisories ICSA-13-011-03 and the Rockwell customer support answers for the affected module and controller families.
  • Restrict network access to TCP/UDP ports 2222 and 44818 using firewalls or segmentation so only trusted engineering and control hosts can reach EtherNet/IP devices.
  • Place control system networks behind zones and conduits per IEC 62443 practice, and avoid exposing CIP ports to untrusted networks.
  • Monitor vendor advisories for replacement or end-of-life guidance on older ControlLogix, CompactLogix, GuardLogix, SoftLogix and MicroLogix revisions that may not receive firmware updates.

Detection

  • Alert on unexpected or unauthorized hosts sending traffic to TCP/UDP ports 2222 and 44818 on EtherNet/IP devices.
  • Baseline normal CIP traffic patterns and flag anomalous packet sizes, rates or sequences directed at those ports.
  • Review device and switch logs for connections to CIP ports originating outside the engineering workstation or control network segment.

This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.

Affected products

17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2012-6441 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2012-6437Rockwellautomation controllogix controllers improper authentication vulnerabilityThe device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…EPSS 7.8%8.5CVE-2012-6439Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 23%7.5CVE-2012-6435Rockwellautomation controllogix controllers improper access control vulnerabilityWhen an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…EPSS 33%7.5CVE-2012-6436Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%7.5CVE-2012-6438Rockwellautomation controllogix controllers memory buffer overflow vulnerabilityThe device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…EPSS 27%4.8CVE-2012-6440Rockwellautomation controllogix controllers improper authentication vulnerabilityThe Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vuln…EPSS 9.3%5.9CVE-2025-68686FortiOS symbolic link patch bypass exposes sensitive informationFortiOS contains an information exposure flaw (CWE-200) that lets a remote unauthenticated attacker bypass the patch for the symbolic link persistenc…KEVEPSS 30%analysed7.5CVE-2026-20133Cisco Catalyst SD-WAN Manager insufficient file system restrictions expose dataCisco Catalyst SD-WAN Software has insufficient file system restrictions that let an attacker read sensitive files on the underlying operating system…KEVEPSS 32%analysed

Source: NIST National Vulnerability Database (record CVE-2012-6441), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.