CVE-2020-5801

Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
29/12/2020
Last modified:
30/12/2020

Description

An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:factorytalk_linx:*:*:*:*:*:*:*:* 6.11 (including)


References to Advisories, Solutions, and Tools