CVE-2023-29464
Rockwell Automation FactoryTalk Linx Vulnerable to Denial-of-Service and Information Disclosure
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.
FactoryTalk Linx, en Rockwell Automation PanelView Plus, permite que un actor de amenazas no autenticado lea datos de la memoria a través de paquetes maliciosos manipulados. Enviar un tamaño mayor que el tamaño del búfer da como resultado una fuga de datos de la memoria, lo que resulta en una divulgación de información. Si el tamaño es lo suficientemente grande, hace que las comunicaciones a través del protocolo industrial común dejen de responder a cualquier tipo de paquete, lo que resulta en una Denegación de Servicio (DoS) para FactoryTalk Linx a través del protocolo industrial común.
CVSS Scores
SSVC
- Decision:Attend
Timeline
- 2023-04-06 CVE Reserved
- 2023-10-13 CVE Published
- 2024-09-17 CVE Updated
- 2024-10-19 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-20: Improper Input Validation
- CWE-787: Out-of-bounds Write
CAPEC
- CAPEC-10: Buffer Overflow via Environment Variables
References (0)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Linx Search vendor "Rockwellautomation" for product "Factorytalk Linx" | 6.20 Search vendor "Rockwellautomation" for product "Factorytalk Linx" and version "6.20" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Linx Search vendor "Rockwellautomation" for product "Factorytalk Linx" | 6.30 Search vendor "Rockwellautomation" for product "Factorytalk Linx" and version "6.30" | - |
Affected
|