### [CVE-2020-5802](https://cve.mitre.org/cgi-bin/cvename.cgi?name=CVE-2020-5802) ![](https://img.shields.io/static/v1?label=Product&message=Rockwell%20FactoryTalk%20Linx&color=blue) ![](https://img.shields.io/static/v1?label=Version&message=n%2Fa&color=blue) ![](https://img.shields.io/static/v1?label=Vulnerability&message=Unauthenticated%20Remote%20Denial%20of%20Service&color=brighgreen) ### Description An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected. ### POC #### Reference - https://www.tenable.com/security/research/tra-2020-71 - https://www.tenable.com/security/research/tra-2020-71 #### Github No PoCs found on GitHub currently.