CVE-2020-27255
Description
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
An unauthenticated remote attacker can trigger a heap overflow in FactoryTalk Linx 6.11 and prior via crafted set attribute requests, leaking sensitive information that could bypass ASLR.
Vulnerability
A heap-based buffer overflow vulnerability exists in Rockwell Automation FactoryTalk Linx version 6.11 and prior [1]. The flaw resides in the handling of set attribute requests, where improper input validation allows a remote, unauthenticated attacker to send specially crafted packets that overwrite heap memory [1]. This affects all versions up to and including 6.11.
Exploitation
An attacker needs network access to a device running an affected version of FactoryTalk Linx [1]. No authentication is required [1]. The attacker sends malicious set attribute requests to the target; no user interaction is needed [1]. The exploitation requires low skill level [1].
Impact
Successful exploitation leaks sensitive information from the heap [1]. This information disclosure could be used to bypass address space layout randomization (ASLR), lowering the bar for further attacks [1]. The CVSS v3 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) [1].
Mitigation
Rockwell Automation has released a fix in a later version; users should update to the latest version of FactoryTalk Linx [1]. As a workaround, users can apply defense-in-depth strategies such as network segmentation and restricting access to trusted hosts [1]. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.
AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.
Affected products
2- FactoryTalk Linx/FactoryTalk Linxdescription
- Range: <=6.11
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1- us-cert.cisa.gov/ics/advisories/icsa-20-329-01mitrex_refsource_MISC
News mentions
0No linked articles in our index yet.