PT-2020-12995 · Rockwell Automation · Rockwell Automation Factorytalk View Se+1
Published
2020-01-30
·
Updated
2021-09-23
·
CVE-2020-12027
CVSS v3.1
4.3
Medium
| Vector | AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation FactoryTalk View SE (affected versions not specified)
Rockwell Automation Studio 5000 (affected versions not specified)
Description
The issue allows a remote, authenticated attacker to potentially gather sensitive information about the system, including hostnames and file paths for certain files. This could be leveraged for reconnaissance efforts. The estimated number of potentially affected devices worldwide is not available. There is no information about real-world incidents where this issue was exploited.
Recommendations
For Rockwell Automation FactoryTalk View SE, enable built-in security features, and follow the guidance in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPS.
For Rockwell Automation Studio 5000, at the moment, there is no information about a newer version that contains a fix for this vulnerability.
Exploit
Information Disclosure
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rockwell Automation Factorytalk View Se
Rockwell Automation Studio 5000