Vulnerability record · CVE-2012-6441 · published 24 January 2013
CVE-2012-6441: Rockwell Automation EtherNet/IP modules expose confidential data via crafted CIP packet
Rockwellautomation · Controllogix Controllers
A specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to expose confidential information. The flaw affects a broad range of ControlLogix, CompactLogix, GuardLogix, SoftLogix, FLEXLogix, FLEX I/O and MicroLogix products, so unpatched industrial control networks carry a confidentiality risk.
Description
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400
AV:N/AC:L/Au:N/C:P/I:N/A:N
Automated analysis
high priorityThe flaw is remotely reachable without authentication on internet-exposed ICS ports and has a very high EPSS score, though it only causes confidentiality loss and has no confirmed exploit or KEV listing.
What it is
A specially crafted CIP packet sent to TCP/UDP ports 2222 or 44818 causes Rockwell Automation EtherNet/IP communication modules and controllers to expose confidential information. The flaw affects a broad range of ControlLogix, CompactLogix, GuardLogix, SoftLogix, FLEXLogix, FLEX I/O and MicroLogix products, so unpatched industrial control networks carry a confidentiality risk.
Impact
An attacker gains read access to confidential information held or passed by the affected device; integrity and availability are not affected per the CVSS vector. The exposure is limited to confidentiality loss, but on ICS equipment that data may include sensitive process or configuration details.
Attack surface
Reachable over the network via CIP traffic to TCP/UDP ports 2222 and 44818; the CVSS vector AV:N/AC:L/Au:N indicates no authentication and no user interaction are required. Any host that can send packets to those ports on an exposed module can attempt the attack.
Exploitation
Not listed in CISA KEV and no ransomware associations are documented; EPSS is high at roughly 0.57 (99th percentile), but the references carry no exploit tags, so public exploit availability is not confirmed by this record.
What to do
- Apply the Rockwell Automation fixes referenced in advisories ICSA-13-011-03 and the Rockwell customer support answers for the affected module and controller families.
- Restrict network access to TCP/UDP ports 2222 and 44818 using firewalls or segmentation so only trusted engineering and control hosts can reach EtherNet/IP devices.
- Place control system networks behind zones and conduits per IEC 62443 practice, and avoid exposing CIP ports to untrusted networks.
- Monitor vendor advisories for replacement or end-of-life guidance on older ControlLogix, CompactLogix, GuardLogix, SoftLogix and MicroLogix revisions that may not receive firmware updates.
Detection
- Alert on unexpected or unauthorized hosts sending traffic to TCP/UDP ports 2222 and 44818 on EtherNet/IP devices.
- Baseline normal CIP traffic patterns and flag anomalous packet sizes, rates or sequences directed at those ports.
- Review device and switch logs for connections to CIP ports originating outside the engineering workstation or control network segment.
This assessment is produced automatically and is not human-reviewed. Verify against the vendor advisory before acting on it.
Affected products
17 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
Track CVE-2012-6441 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2012-6441), CISA KEV, FIRST EPSS (scores of 2026-09-27). This page is refreshed as NVD updates the record.