CVE-2020-14478: IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2020-14478.
What is the severity of CVE-2020-14478?
The severity of CVE-2020-14478 is high with a score of 7.1.
How does this vulnerability occur?
This vulnerability occurs due to a weakly configured XML file that can be exploited using an XML External Entity (XXE) attack.
What can an attacker do if they successfully exploit this vulnerability?
If an attacker successfully exploits this vulnerability, they could cause a denial-of-service condition and gain access to local or remote content.
Is there a fix available for this vulnerability?
It is recommended to update to Rockwell Automation FactoryTalk Services Platform version 6.11.01 or later to fix this vulnerability.