PT-2020-16667 · Rockwell Automation · Factorytalk Linx
Published
2020-11-24
·
Updated
2020-11-30
·
CVE-2020-27253
CVSS v2.0
7.8
High
| Vector | AV:N/AC:L/Au:N/C:N/I:N/A:C |
Name of the Vulnerable Software and Affected Versions
FactoryTalk Linx versions prior to 6.11
Description
A flaw exists in the Ingress/Egress checks routine, allowing a remote, unauthenticated attacker to craft a malicious packet, resulting in a denial-of-service condition on the device.
Recommendations
For versions prior to 6.11, update to a version that includes a fix for this issue to prevent a denial-of-service condition. As a temporary workaround, consider implementing network traffic filtering to restrict malicious packets from reaching the device.
Fix
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Factorytalk Linx