Aller au contenu

Fiche vulnérabilité

CVE-2023-29464 : faille critique rockwellautomation factorytalk linx (CVSS 9.1)

Description

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

En bref

Sévérité
Critique (CVSS 9.1)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
13 oct. 2023
Dernière mise à jour
17 juin 2026

Produits concernés

  • rockwellautomation factorytalk linx

Références

Rechercher une autre vulnérabilité dans la base CVE