Vulnerability Details CVE-2020-5801
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 44.7%
CVSS Severity
CVSS v3 Score 7.5
CVSS v2 Score 5.0
Products affected by CVE-2020-5801
-
cpe:2.3:a:rockwellautomation:factorytalk_linx:6.00
-
cpe:2.3:a:rockwellautomation:factorytalk_linx:6.10
-
cpe:2.3:a:rockwellautomation:factorytalk_linx:6.11