CVE-2012-6442

HIGHPre-NVD 7.57.7▲
EchelonGraph scoreHIGH confidence

Score elevated to 7.7 because EPSS predicts 36% probability of exploitation within the next 30 days (98th percentile of EPSS-scored CVEs). CISA-ADP (Vulnrichment) CVSS v3.1 baseline 7.5 retained for reference (NVD's own analysis pending). Confidence: see factors.

Triggered by: EPSS exploit prediction ≥85%
Sources: cisa-adp, epss, ghsa
Elevated
7.7EG
EchelonGraph verdictPlan mitigationSerious severity, but no confirmed exploitation yet.
  • High severity, but no confirmed exploitation yet
CISA-KEV: Not listedEPSS PROB: 36%CVSS: 7.5Exploit: Elevated riskExposed services: —

No fix is confirmed yet — apply a workaround or compensating control (WAF / firewall / segmentation) and watch for the fix.

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected devices.

Rockwell Automation EtherNet/IP products; 1756-ENBT, 1756-EWEB, 1768-ENBT, and 1768-EWEB communication modules; CompactLogix L32E and L35E controllers; 1788-ENBT FLEXLogix adapter; 1794-AENTR FLEX I/O EtherNet/IP adapter; ControlLogix 18 and earlier; CompactLogix 18 and earlier; GuardLogix 18 and earlier; SoftLogix 18 and earlier; CompactLogix controllers 19 and earlier; SoftLogix controllers 19 and earlier; ControlLogix controllers 20 and earlier; GuardLogix controllers 20 and earlier; and MicroLogix 1100 and 1400

Internet exposure

The internet-exposure footprint is temporarily unavailable — the KEV-Exposure radar's record for this CVE could not be loaded just now. That is not a finding of zero exposed services; please retry shortly.

CVSS v3
7.5
EG Score
7.7HIGHhigh confidence
EG Risk
66
EG Risk 66/100CISA SSVC

EG Risk is EchelonGraph's 0–100 priority score: it fuses intrinsic severity with real-world exploitation and automatability so you can rank equal-severity CVEs and fix the most dangerous first. Higher = act sooner. Distinct from the 0–10 EG Score (severity).

How it’s computed
Severity77% × 45%
Exploitation40% × 40%
Automatability100% × 15%
CISA SSVC: Track at low or medium mission impact; Attend at high (mission-essential systems).
Action: No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.
EPSS PROB
36%
EPSS %ILE
98th
KEV
Not listed

CISA SSVCTrack at low or medium mission impact; Attend at high (mission-essential systems).

No fix is confirmed yet. Restrict network exposure of the affected system or apply the vendor's mitigation within your standard update timelines at low or medium mission impact and sooner than that at high, and watch the vendor's advisory for the fix.

Exploitation none (CISA Vulnrichment) · Automatable yes (CISA Vulnrichment) · Technical impact partial (CISA Vulnrichment). Mission impact is CISA's Mission & Well-being decision point, and only you can judge it: high means the affected system is essential to your organisation's mission, or its compromise could cause irreversible harm to people. CISA's decision table

Published

January 24, 2013

Last Modified

June 3, 2026

Advisory Details (1)

Auto-updated Jun 6, 2026
No fix on record yet. Sources: cisa.
GitHub Security Advisories

GHSA-5v56-2w57-vj72

{CVE-2012-6442}

Affected: 7.5

github

Vendor Advisories for CVE-2012-6442

Vendor advisories for this CVE are temporarily unavailable — the list could not be loaded just now. That is not a sign that none exist; please retry shortly.

Related CVEs are temporarily unavailable — the same-product, same-vendor and same-CWE lists could not be loaded just now. That is not a sign that none exist; please retry shortly.

Frequently asked(5)

What is CVE-2012-6442?
CVE-2012-6442 is a high vulnerability published on January 24, 2013. When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication…
When was CVE-2012-6442 disclosed?
CVE-2012-6442 was first published on January 24, 2013, with the most recent update on June 3, 2026. EchelonGraph re-ingests CVE updates from NVD on a 2-hour cycle, so this page reflects the latest published state.
Is CVE-2012-6442 actively exploited?
CVE-2012-6442 is not currently on CISA's Known Exploited Vulnerabilities catalog. FIRST EPSS estimates a 36% probability of exploitation in the next 30 days (98th percentile of EPSS-scored CVEs).
What is the CVSS score of CVE-2012-6442?
CVE-2012-6442 has a CVSS v3.1 base score of 7.5 (CISA-ADP / Vulnrichment enrichment; NVD's own analysis pending). EchelonGraph synthesises NVD + CISA KEV + FIRST EPSS + GHSA into a combined EG score of 7.7 (HIGH).
How do I remediate CVE-2012-6442?
No fix for CVE-2012-6442 is confirmed yet. Until one is published, restrict network exposure of the affected system or apply the vendor's mitigation — for example, keep it off the internet or limit it to trusted networks — and watch the vendor's advisory for the fix.

Dependency Blast Radius

Explore the affected products and dependency analysis for CVE-2012-6442

Explore →

Is Your Infrastructure Affected by CVE-2012-6442?

EchelonGraph automatically scans your cloud infrastructure and maps CVE exposure using blast radius analysis.