An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.
Metrics
Affected Vendors & Products
Advisories
Source | ID | Title |
---|---|---|
![]() |
EUVD-2020-26959 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected. |
Fixes
Solution
No solution given by the vendor.
Workaround
No workaround given by the vendor.
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2020-71 |
![]() ![]() |
History
No history.

Status: PUBLISHED
Assigner: tenable
Published:
Updated: 2024-08-04T08:39:25.932Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5802

No data.

Status : Modified
Published: 2020-12-29T16:15:14.840
Modified: 2024-11-21T05:34:37.430
Link: CVE-2020-5802

No data.

No data.