CVE-2023-29464

HIGH

FactoryTalk Linx - Unauthenticated Information Disclosure and Denial of Service via Malicious Packet Size

Title source: llm
STIX 2.1

Description

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.

References (1)

Core 1
Core References

Scores

CVSS v3 8.2
EPSS 0.0254
EPSS Percentile 85.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-20 CWE-787
Status published
Products (2)
rockwellautomation/factorytalk_linx 6.20
rockwellautomation/factorytalk_linx 6.30
Published Oct 13, 2023
Tracked Since Feb 18, 2026