CVE-2023-29464
HIGHFactoryTalk Linx - Unauthenticated Information Disclosure and Denial of Service via Malicious Packet Size
Title source: llmDescription
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes communications over the common industrial protocol to become unresponsive to any type of packet, resulting in a denial-of-service to FactoryTalk Linx over the common industrial protocol.
References (1)
Core 1
Core References
Permissions Required, Vendor Advisory
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141040
Scores
CVSS v3
8.2
EPSS
0.0254
EPSS Percentile
85.7%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:H
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-20
CWE-787
Status
published
Products (2)
rockwellautomation/factorytalk_linx
6.20
rockwellautomation/factorytalk_linx
6.30
Published
Oct 13, 2023
Tracked Since
Feb 18, 2026