First published: Mon Mar 23 2020(Updated: )
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Factorytalk Services Platform |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID of this Rockwell Automation vulnerability is CVE-2020-6967.
The title of this Rockwell Automation vulnerability is 'In Rockwell Automation all versions of FactoryTalk Diagnostics software a subsystem of the FactoryTalk Services Platform'.
The severity of CVE-2020-6967 is critical, with a severity value of 9.8.
All versions of Rockwell Automation FactoryTalk Services Platform are affected by this vulnerability.
This vulnerability can be exploited by insecurely deserializing untrusted data through the .NET Remoting endpoint exposed by FactoryTalk Diagnostics software.