VendorsRockwell Automationfactorytalk_linxany version
Vulnerabilities

Rockwell Automation FactoryTalk Linx any version

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

9CVEs
CVE-2020-27251
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.
Published 2020-11-26 · Modified
9.8EPSS 0.068
CVE-2025-7972
Rockwell Automation FactoryTalk® Linx Network Browser Security Bypass Vulnerability
Published 2025-08-14 · Analyzed
9.1EPSS 0.005
CVE-2025-9067
Rockwell Automation FactoryTalk® Linx Privilege Escalation Vulnerabilities
Published 2025-10-14 · Analyzed
8.5EPSS 0.002
CVE-2025-9068
Rockwell Automation FactoryTalk® Linx Privilege Escalation Vulnerabilities
Published 2025-10-14 · Analyzed
8.5EPSS 0.002
CVE-2020-27253
A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device.
Published 2020-11-26 · Modified
7.8EPSS 0.019
CVE-2020-5802
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx are affected.
Published 2020-12-29 · Modified
7.5EPSS 0.388
CVE-2020-5801
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
Published 2020-12-29 · Modified
7.5EPSS 0.252
CVE-2020-27255
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).
Published 2020-11-26 · Modified
7.5EPSS 0.039
CVE-2020-5806
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
Published 2020-12-29 · Modified
5.5EPSS 0.048