#VU25497 Deserialization of Untrusted Data in FactoryTalk Diagnostics - CVE-2020-6967
Published: February 21, 2020
FactoryTalk Diagnostics
Rockwell Automation
Description
The vulnerability allows a remote attacker to execute arbitrary code on the target system.
The vulnerability exists due to the affected software exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082. A remote attacker can pass specially crafted data to the application and execute arbitrary code on the target system.
Successful exploitation of this vulnerability may result in complete compromise of vulnerable system.