Remote Code Execution Vulnerability in FactoryTalk Diagnostics by Rockwell Automation
CVE-2020-5807
What is CVE-2020-5807?
An unauthenticated remote attacker can exploit a vulnerability in FactoryTalk Diagnostics by sending specially crafted data to RsvcHost.exe, which is listening on TCP port 5241. This exploitation allows the attacker to manipulate entries in the FactoryTalk Diagnostics event log. When a local user accesses this log via the FactoryTalk Diagnostics Viewer (FTDiagViewer.exe), it can cause an unhandled exception due to excessively long fields in the log entry, potentially leading to unexpected behavior or crashes in the application.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Rockwell FactoryTalk Diagnostics All versions of FactoryTalk Diagnostics
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
