CVE-2020-5802
29.12.2020, 16:15
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.Enginsight
| Vendor | Product | Version |
|---|---|---|
| rockwellautomation | factorytalk_linx | 𝑥 ≤ 6.11 |
𝑥
= Vulnerable software versions