CVE Vulnerabilities

CVE-2020-12025

Improper Restriction of XML External Entity Reference

Published: Jul 14, 2020 | Modified: Nov 21, 2024
CVSS 3.x
3.3
LOW
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
CVSS 2.x
4.3 MEDIUM
AV:N/AC:M/Au:N/C:P/I:N/A:N
RedHat/V2
RedHat/V3
Ubuntu

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Studio_5000_logix_designer Rockwellautomation 32.00 (including) 32.00 (including)
Studio_5000_logix_designer Rockwellautomation 32.01 (including) 32.01 (including)
Studio_5000_logix_designer Rockwellautomation 32.02 (including) 32.02 (including)

Potential Mitigations

References