This Updated Advisory is a follow-up to the original Advisory titled “ICSA-11-273-03—Rockwell RSLogix denial-of-Service Vulnerability” that was published September 30, 2011 on the ICS-CERT web page. ICS-CERT is aware of a public report of a denial-of-service vulnerability in Rockwell Automation’s RSLogix application. --------- Begin Update X Part 1 of 2 -------- Rockwell has produced a patch that mitigates this vulnerability for all affected versions of FactoryTalk Services Platform and RSLogix 5000. --------- End Update X Part 1 of 2 ---------- AFFECTED PRODUCTS According to Rockwell Automation, the following products are affected: • RSLogix 5000 software Versions V17, V18, and V19 • All FactoryTalk-branded software of specific Versions CPR9 and CPR9-SR1 through SR4. IMPACT Successful exploitation of this vulnerability could result in a denial-of-service. Impact to individual organizations depends on many factors that are unique to each organization. ICS-CERT recommends that organizations evaluate the impact of this vulnerability based on their operational environment, architecture, and product implementation.