CVE-2020-6967: Critical severity rockwellautomation Factorytalk Services Platform vulnerability
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this Rockwell Automation vulnerability?
The vulnerability ID of this Rockwell Automation vulnerability is CVE-2020-6967.
What is the title of this Rockwell Automation vulnerability?
The title of this Rockwell Automation vulnerability is 'In Rockwell Automation all versions of FactoryTalk Diagnostics software a subsystem of the FactoryTalk Services Platform'.
What is the severity of CVE-2020-6967?
The severity of CVE-2020-6967 is critical, with a severity value of 9.8.
Which software versions are affected by this vulnerability?
All versions of Rockwell Automation FactoryTalk Services Platform are affected by this vulnerability.
How can this vulnerability be exploited?
This vulnerability can be exploited by insecurely deserializing untrusted data through the .NET Remoting endpoint exposed by FactoryTalk Diagnostics software.