Infinite loop in GoAhead - CVE-2019-5097
Published: December 3, 2019
Vulnerability details
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to infinite loop in the processing of multi-part/form-data requests in the base GoAhead web server application. A remote attacker can send a specially crafted HTTP request, consume all available system resources and cause denial of service conditions.
Affected software
1732E-IF4M12R/A
1756-EN2TSC/B
5069-AEN2TR
1747-AENTR
1732E-IB8M8SOER
1732E-OB8M8SR/A
1732E-8IOLM12R
1732E-OF4M12R/A
1732E-8CFGM8R/A
1732E-IR4IM12R/A
1732E-IT4IM12R/A
1756-EN2TR/C
1756-HIST1G/A
1756-HIST2G/A
1769-AENTR
1756-HIST2G/B
1756-EN2T/D
Compact GuardLogix 5380
CompactLogix 5380
GuardLogix 5580
ControlLogix 5580
1756-EN2TP/A
1756-EN2F/C
1765 – EN3TR/B
1756- EN2T/D
CompactLogix 5480
How to mitigate CVE-2019-5097
Compact GuardLogix 5380 - update to 32.016
CompactLogix 5380 - update to 32.016
GuardLogix 5580 - update to 32.016
ControlLogix 5580 - update to 32.016
1756-EN2TP/A - update to 11.002
1756-EN2F/C - update to 11.002
1756-EN2TR/C - update to 11.002
CompactLogix 5480 - update to 32.016
1756-HIST1G/A - addressed in versions B 5.104, C 7.100
1756-HIST2G/A - addressed in versions B 5.104, C 7.100
1769-AENTR - update to 1.003
1756-HIST2G/B - update to 5.104
1756-EN2T/D - update to 11.002