CVE-2020-12031: Rockwell Automation FactoryTalk View SE
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the vulnerability ID for this vulnerability?
The vulnerability ID for this vulnerability is CVE-2020-12031.
What is the severity of CVE-2020-12031?
CVE-2020-12031 has a severity rating of 7.8 (high).
How does CVE-2020-12031 impact Rockwell Automation FactoryTalk View?
CVE-2020-12031 allows a local, authenticated attacker to corrupt the memory space and execute arbitrary code in Rockwell Automation FactoryTalk View SE.
What is the recommended solution for CVE-2020-12031?
To mitigate CVE-2020-12031, Rockwell Automation recommends applying patch 1126290.
Where can I find more information about CVE-2020-12031?
You can find more information about CVE-2020-12031 at the following references: - Rockwell Automation: https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126944 - US-CERT: https://us-cert.cisa.gov/ics/advisories/icsa-20-170-05