CVE-2025-7972
- EPSS 0.02%
- Published 14.08.2025 14:47:46
- Last modified 15.08.2025 13:12:51
A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
CVE-2023-29464
- EPSS 2.54%
- Published 13.10.2023 13:15:11
- Last modified 21.11.2024 07:57:07
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting i...
CVE-2020-5801
- EPSS 0.22%
- Published 29.12.2020 16:15:14
- Last modified 21.11.2024 05:34:37
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6....
CVE-2020-5802
- EPSS 0.17%
- Published 29.12.2020 16:15:14
- Last modified 21.11.2024 05:34:37
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.e...
CVE-2020-5806
- EPSS 0.01%
- Published 29.12.2020 16:15:14
- Last modified 21.11.2024 05:34:37
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in Fact...
CVE-2020-27251
- EPSS 19.75%
- Published 26.11.2020 02:15:12
- Last modified 21.11.2024 05:20:56
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.
CVE-2020-27253
- EPSS 0.03%
- Published 26.11.2020 02:15:12
- Last modified 21.11.2024 05:20:56
A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on th...
CVE-2020-27255
- EPSS 1.52%
- Published 26.11.2020 02:15:12
- Last modified 21.11.2024 05:20:57
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive informatio...
CVE-2020-11999
- EPSS 0.09%
- Published 15.06.2020 20:15:11
- Last modified 21.11.2024 04:59:05
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 an...
CVE-2020-12001
- EPSS 0.08%
- Published 15.06.2020 20:15:11
- Last modified 21.11.2024 04:59:05
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 an...