VYPR
Unrated severityNVD Advisory· Published Sep 20, 2018· Updated Sep 16, 2024

CVE-2018-14827

CVE-2018-14827

Description

Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software application to stop responding and crash. The user must restart the software to regain functionality.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Rockwell Automation RSLinx Classic versions <=4.00.01 are vulnerable to multiple CIP/Ethernet/IP packet flaws allowing remote, unauthenticated denial of service or arbitrary code execution.

Vulnerability

Rockwell Automation RSLinx Classic versions 4.00.01 and prior are affected by a stack-based buffer overflow (CVE-2018-14829), a heap-based buffer overflow (CVE-2018-14821), and a resource exhaustion flaw (CVE-2018-14827) [1]. These vulnerabilities exist in the handling of specially crafted Common Industrial Protocol (CIP) and Ethernet/IP packets received on TCP port 44818 [1]. No authentication or user interaction is required to reach the vulnerable code path.

Exploitation

An unauthenticated remote attacker can send a malformed CIP or Ethernet/IP packet to port 44818 of an affected RSLinx Classic instance [1]. The attacker does not need any prior network access or credentials. Exploitation requires only low skill level and can be performed over the network without any user interaction [1].

Impact

Successful exploitation can cause the RSLinx Classic software to terminate or stop responding, requiring the user to manually restart the application to regain functionality [1]. The stack-based buffer overflow (CVE-2018-14829) also has the potential to allow remote arbitrary code execution on the device, leading to full compromise of confidentiality, integrity, and availability (CVSS 10.0) [1]. The heap-based buffer overflow and resource exhaustion flaws primarily result in a denial-of-service condition [1].

Mitigation

Rockwell Automation has not released a patched version as of the advisory publication date (2018-09-20) [1]. Operators of affected RSLinx Classic versions should restrict network access to port 44818 to trusted hosts only, segment the control network, and monitor ICS-CERT advisory ICSA-18-263-02 for updates [1]. The vulnerabilities are not known to be listed on CISA's Known Exploited Vulnerabilities (KEV) catalog as of the reference publication.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.