CVE-2020-5807
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log.
Does this matter?
EPSS puts the probability of exploitation in the next 30 days at 33.8%, higher than 98% of all known CVEs. Patch or mitigate before the next change window.
Description
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer (FTDiagViewer.exe) to view the log entry. Observed in FactoryTalk Diagnostics 6.11. All versions of FactoryTalk Diagnostics are affected.
- CVSS 3.1
- 7.5 HIGHCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 33.84% probability · 98th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-755
- Affected
- rockwellautomation/factorytalk diagnostics
- Source
- vulnreport@tenable.com
References
- https://www.tenable.com/security/research/tra-2020-71Third Party Advisory
- https://www.tenable.com/security/research/tra-2020-71Third Party Advisory
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.