CVE-2012-6441
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products.
1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules.
CompactLogix L32E and L35E controllers.
1788-ENBT FLEXLogix adapter.
1794-AENTR FLEX I/O EtherNet/IP adapter.
ControlLogix 18 and earlier.
CompactLogix 18 and earlier.
GuardLogix 18 and earlier.
SoftLogix 18 and earlier.
CompactLogix controllers 19 and earlier.
SoftLogix controllers 19 and earlier.
ControlLogix controllers 20 and earlier.
GuardLogix controllers 20 and earlier.
and MicroLogix 1100 and 1400.
- EPSS ≥ 0.50 - high probability of exploitation in the next 30 days
- EPSS percentile: top 1% of all CVEs by exploitation likelihood
ATT&CK techniques
20Techniques this CVE enables - linked via CWECAPECATT&CK. High◆ = named directly in ATT&CK or Nuclei templates.
CAPEC attack patterns
12Attack patterns this CVE enables - the bridge from weakness to ATT&CK technique.