CVE-2020-12031
Last modified
CVE-2020-12031 is a high-severity vulnerability rated 7.8/10 on the CVSS scale. In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. EPSS estimates a 0.60% chance of exploitation in the next 30 days.
Description
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk View | All versions |
References
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05Third Party Advisory, US Government Resource
- https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05Third Party Advisory, US Government Resource
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2020-12031?
How severe is CVE-2020-12031?
How do I fix CVE-2020-12031?
Are you affected by CVE-2020-12031?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
