Lucene search

K
cvelistIcscertCVELIST:CVE-2020-12027
HistoryJul 20, 2020 - 3:13 p.m.

CVE-2020-12027 Rockwell Automation FactoryTalk View SE

2020-07-2015:13:36
CWE-200
icscert
www.cve.org
6
rockwell automation
factorytalk view se
cve-2020-12027
disclosure
reconnaissance
security features
ipsec
https

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0.057

Percentile

93.4%

All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users should follow guidance found in knowledge base articles 109056 and 1126943 to set up IPSec and/or HTTPs.

CNA Affected

[
  {
    "product": "FactoryTalk View SE",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "all versions"
      }
    ]
  }
]

CVSS3

4.3

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

LOW

Integrity Impact

NONE

Availability Impact

NONE

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:L/I:N/A:N

AI Score

4.3

Confidence

High

EPSS

0.057

Percentile

93.4%