8.4
CWE
611
Advisory Published
Updated

CVE-2020-14478: IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611

First published: Thu Feb 24 2022(Updated: )

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

Credit: ics-cert@hq.dhs.gov

Affected SoftwareAffected VersionHow to fix
Rockwellautomation Factorytalk Services Platform<=6.11.00
Rockwell Automation Versions 6.11.00 and earlier

Never miss a vulnerability like this again

Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.

Parent vulnerabilities

(Appears in the following advisories)

Frequently Asked Questions

  • What is the vulnerability ID for this issue?

    The vulnerability ID for this issue is CVE-2020-14478.

  • What is the severity of CVE-2020-14478?

    The severity of CVE-2020-14478 is high with a score of 7.1.

  • How does this vulnerability occur?

    This vulnerability occurs due to a weakly configured XML file that can be exploited using an XML External Entity (XXE) attack.

  • What can an attacker do if they successfully exploit this vulnerability?

    If an attacker successfully exploits this vulnerability, they could cause a denial-of-service condition and gain access to local or remote content.

  • Is there a fix available for this vulnerability?

    It is recommended to update to Rockwell Automation FactoryTalk Services Platform version 6.11.01 or later to fix this vulnerability.

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2024 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203