Lucene search

K
zdiTeam FLASHBACK: Pedro Ribeiro ([email protected]|@pedrib1337) and Radek Domanski (@RabbitPro)ZDI-20-729
HistoryJun 22, 2020 - 12:00 a.m.

(Pwn2Own) Rockwell Automation FactoryTalk View SE Backup Missing Authentication for Critical Function Vulnerability

2020-06-2200:00:00
Team FLASHBACK: Pedro Ribeiro ([email protected]|@pedrib1337) and Radek Domanski (@RabbitPro)
www.zerodayinitiative.com
22

EPSS

0.035

Percentile

91.6%

This vulnerability allows remote attackers to create arbitrary files on affected installations of Rockwell Automation FactoryTalk View SE. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of project backups. The issue results from lack of authorization prior to initiating a backup. An attacker can leverage this in conjunction with other vulnerability to execute code in the context of SYSTEM.