First published: Thu Nov 26 2020(Updated: )
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Factorytalk Linx | <=6.11 | |
Rockwell Automation FactoryTalk Linx: Version 6.11 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27255 is a heap overflow vulnerability in FactoryTalk Linx Version 6.11 and prior.
The severity of CVE-2020-27255 is high, with a CVSS score of 7.5.
CVE-2020-27255 allows a remote, unauthenticated attacker to send malicious set attribute requests, leading to sensitive information disclosure.
The potential impact of CVE-2020-27255 is the leaking of sensitive information, which may result in further exploitation.
At the time of writing, there is no available fix for CVE-2020-27255. It is recommended to follow the mitigation steps provided by the vendor and monitor for updates.