CVE-2012-6435

HIGHCVSS 7.5
7.5CVSS
EchelonGraph verdictPlan a fixSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: —CVSS: 7.5Exploit: None knownExposed services: —

A fix is available — apply it.

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices.

Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Internet exposure

The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.

CVSS v3
7.5
EchelonGraph score
Not yet assessedEchelonGraph has no severity assessment for this CVE yet. This is not a rating of zero.
EG Score
—
EG Risk
—
EPSS PROB
—
EPSS %ILE
—
KEV
Not listed

Published

January 24, 2013

Last Modified

June 16, 2026

Advisory Details (1)

Auto-updated Jul 17, 2026
Patch available. Sources: cisa.
GitHub Security Advisories

GHSA-86cc-g342-r35v

{CVE-2012-6435}

Affected: 7.5

github

Vendor Advisories for CVE-2012-6435

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Weakness Classification(1)

MITRE Common Weakness Enumeration — the root-cause categories this CVE belongs to.

Frequently asked(4)

What is CVE-2012-6435?
CVE-2012-6435 is a high vulnerability published on January 24, 2013. When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability…
When was CVE-2012-6435 disclosed?
CVE-2012-6435 was first published on January 24, 2013, with the most recent update on June 16, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
What is the CVSS score of CVE-2012-6435?
CVE-2012-6435 has a CVSS base score of 7.5.
How do I remediate CVE-2012-6435?
A fix for CVE-2012-6435 is available: update to the fixed version the vendor names in its advisory.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2012-6435

Explore →

Is Your Infrastructure Affected by CVE-2012-6435?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.