Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-q4jm-4p9g-2h6g

Опубликовано: 24 мая 2022
Источник: github
Github: Не прошло ревью

Описание

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).

EPSS

Процентиль: 81%
0.01516
Низкий

Дефекты

CWE-122

Связанные уязвимости

CVSS3: 7.5
nvd
около 5 лет назад

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address space layout randomization (ASLR).

CVSS3: 5.3
fstec
около 5 лет назад

Уязвимость программного обеспечения системы автоматизации FactoryTalk Linx, связанная с выходом операции за границы буфера в памяти, позволяющая нарушителю обойти механизм защиты ASLR и получить доступ к конфиденциальной информации

EPSS

Процентиль: 81%
0.01516
Низкий

Дефекты

CWE-122