CVE Vulnerabilities

CVE-2020-14478

Improper Restriction of XML External Entity Reference

Published: Feb 24, 2022 | Modified: Apr 17, 2025
CVSS 3.x
7.1
HIGH
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:H
CVSS 2.x
5.6 MEDIUM
AV:L/AC:L/Au:N/C:C/I:N/A:P
RedHat/V2
RedHat/V3
Ubuntu

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.

Weakness

The product processes an XML document that can contain XML entities with URIs that resolve to documents outside of the intended sphere of control, causing the product to embed incorrect documents into its output.

Affected Software

Name Vendor Start Version End Version
Factorytalk_services_platform Rockwellautomation * 6.11.00 (including)

Potential Mitigations

References