QID 591428

Date Published: 2023-12-22

QID 591428: Rockwell Automation FactoryTalk Linx Denial of Service (DoS) and Information Disclosure Vulnerabilities (ICSA-23-290-02)

FactoryTalk Linx is a communications platform and server service from Rockwell Automation that provides control system information. This software delivers a solution from small applications running on a single computer with a single controller, to large distributed and even redundant data server configurations communicating with large automation systems.

Affected Products:
FactoryTalk Linx Versions prior to 6.20.00 and 6.30.22.278

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of Rockwell using the Registry Key "HKLM\SOFTWARE\Rockwell Software"

Vulnerable version of FactoryTalk Linx is prone to Denial of Service and/or Information Disclosure Vulnerabilities

  • CVSS V3 rated as Critical - 9.1 severity.
  • CVSS V2 rated as Critical - 8.5 severity.
  • Solution

    Customers are advised to refer to ICSA-23-290-02 for more information on this.

    CVEs related to QID 591428

    Software Advisories
    Advisory ID Software Component Link
    FactoryTalk Linx PN1652 URL Logo rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141040
    ICSA-23-290-02 URL Logo www.cisa.gov/news-events/ics-advisories/icsa-23-290-02