VYPR
Unrated severityNVD Advisory· Published Nov 26, 2020· Updated Aug 4, 2024

CVE-2020-27255

CVE-2020-27255

Description

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

An unauthenticated remote attacker can trigger a heap overflow in FactoryTalk Linx 6.11 and prior via crafted set attribute requests, leaking sensitive information that could bypass ASLR.

Vulnerability

A heap-based buffer overflow vulnerability exists in Rockwell Automation FactoryTalk Linx version 6.11 and prior [1]. The flaw resides in the handling of set attribute requests, where improper input validation allows a remote, unauthenticated attacker to send specially crafted packets that overwrite heap memory [1]. This affects all versions up to and including 6.11.

Exploitation

An attacker needs network access to a device running an affected version of FactoryTalk Linx [1]. No authentication is required [1]. The attacker sends malicious set attribute requests to the target; no user interaction is needed [1]. The exploitation requires low skill level [1].

Impact

Successful exploitation leaks sensitive information from the heap [1]. This information disclosure could be used to bypass address space layout randomization (ASLR), lowering the bar for further attacks [1]. The CVSS v3 base score is 5.3 (AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:N/A:N) [1].

Mitigation

Rockwell Automation has released a fix in a later version; users should update to the latest version of FactoryTalk Linx [1]. As a workaround, users can apply defense-in-depth strategies such as network segmentation and restricting access to trusted hosts [1]. The vulnerability is not listed in CISA's Known Exploited Vulnerabilities catalog as of the publication date.

AI Insight generated on May 26, 2026. Synthesized from this CVE's description and the cited reference URLs; citations are validated against the source bundle.

Affected products

2

Patches

0

No patches discovered yet.

Vulnerability mechanics

AI mechanics synthesis has not run for this CVE yet.

References

1

News mentions

0

No linked articles in our index yet.