CVE-2020-27255

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).
References
Link Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-329-01 Third Party Advisory US Government Resource
https://us-cert.cisa.gov/ics/advisories/icsa-20-329-01 Third Party Advisory US Government Resource
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_linx:*:*:*:*:*:*:*:*

History

21 Nov 2024, 05:20

Type Values Removed Values Added
References () https://us-cert.cisa.gov/ics/advisories/icsa-20-329-01 - Third Party Advisory, US Government Resource () https://us-cert.cisa.gov/ics/advisories/icsa-20-329-01 - Third Party Advisory, US Government Resource

Information

Published : 2020-11-26 02:15

Updated : 2024-11-21 05:20


NVD link : CVE-2020-27255

Mitre link : CVE-2020-27255

CVE.ORG link : CVE-2020-27255


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_linx
CWE
CWE-122

Heap-based Buffer Overflow