Vulnerability Description
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk Linx | <= 6.11 |
Related Weaknesses (CWE)
References
- https://www.tenable.com/security/research/tra-2020-71Third Party Advisory
- https://www.tenable.com/security/research/tra-2020-71Third Party Advisory
FAQ
What is CVE-2020-5801?
CVE-2020-5801 is a vulnerability with a CVSS score of 7.5 (HIGH). An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in pr...
How severe is CVE-2020-5801?
CVE-2020-5801 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2020-5801?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk Linx.