Lucene search

K
cveIcscertCVE-2020-12028
HistoryJul 20, 2020 - 4:15 p.m.

CVE-2020-12028

2020-07-2016:15:12
CWE-264
CWE-306
icscert
web.nvd.nist.gov
100
cve-2020-12028
factorytalk view sea
remote
authenticated attack
data interaction
permissions
rockwell automation
ipsec
https
security features

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0.035

Percentile

91.6%

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

Affected configurations

Nvd
Node
rockwellautomationfactorytalk_viewse
VendorProductVersionCPE
rockwellautomationfactorytalk_view*cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:*

CNA Affected

[
  {
    "product": "FactoryTalk View SE",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "all versions"
      }
    ]
  }
]

CVSS2

5.5

Attack Vector

NETWORK

Attack Complexity

LOW

Authentication

SINGLE

Confidentiality Impact

PARTIAL

Integrity Impact

PARTIAL

Availability Impact

NONE

AV:N/AC:L/Au:S/C:P/I:P/A:N

CVSS3

8.1

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:N

AI Score

7.8

Confidence

High

EPSS

0.035

Percentile

91.6%