Security Advisory

CVE-2020-5802

CVE vulnerability detail — eXtreme Datacenter Security Operations

Published 2020-12-29 15:04:26
Last updated 2024-08-04 08:39:25
Assigner tenable
State PUBLISHED

Description

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.