PT-2020-12997 · Rockwell Automation · Factorytalk View Se
Published
2020-01-30
·
Updated
2022-01-04
·
CVE-2020-12029
CVSS v3.1
9.0
Critical
| Vector | AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions
FactoryTalk View SE versions (affected versions not specified)
Description
The issue is related to improper validation of input filenames within a project directory, allowing a remote, unauthenticated attacker to potentially execute a crafted file on a remote endpoint, resulting in remote code execution (RCE).
Recommendations
Apply patch 1126289, but first ensure the patch rollup dated 06 Apr 2020 or later is installed.
As a temporary workaround, consider restricting access to the project directory to minimize the risk of exploitation.
Exploit
Fix
Path traversal
Relative Path Traversal
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Factorytalk View Se