An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.
Metrics
Affected Vendors & Products
References
Link | Providers |
---|---|
https://www.tenable.com/security/research/tra-2020-71 |
History
No history.
MITRE
Status: PUBLISHED
Assigner: tenable
Published: 2020-12-29T15:04:26
Updated: 2024-08-04T08:39:25.932Z
Reserved: 2020-01-06T00:00:00
Link: CVE-2020-5802
Vulnrichment
No data.
NVD
Status : Modified
Published: 2020-12-29T16:15:14.840
Modified: 2024-11-21T05:34:37.430
Link: CVE-2020-5802
Redhat
No data.