Buffer overflow in Rockwell Automation products - CVE-2020-12038
Published: May 20, 2020
EDS Subsystem
RSLinx Classic
FactoryTalk Linx
RSNetWorx software
Studio 5000 Logix Designer
Rockwell Automation
Description
The vulnerability allows a remote attacker to perform a denial of service (DoS) attack.
The vulnerability exists due to a boundary error in the algorithm that matches square brackets in the EDS subsystem. A remote authenticated attacker can create a specially crafted EDS file, trick the victim into opening it, trigger memory corruption and cause a denial of service condition on the target system.