RULE(RULE ID:713942)

Rule General Information
Release Date: 2020-05-18
Rule Name: Rockwell Automation FactoryTalk RNADiagnosticsSrv Deserialization Vulnerability -2 (CVE-2020-6967)
Severity:
CVE ID:
Rule Protection Details
Description: In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
Impact: An attacker could exploit this vulnerability to have unspecified effect.
Affected OS: Windows, Linux, FreeBSD, Solaris, Other Unix, Mac OS
Reference: https://www.us-cert.gov/ics/advisories/icsa-20-051-02
Solutions
The vendors have released upgrade patches to fix vulnerabilities, please visit:
https://www.rockwellautomation.com/