File Parsing Vulnerability in FactoryTalk Linx and Related Products by Rockwell Automation
CVE-2020-12001
Key Information:
What is CVE-2020-12001?
Rockwell Automation's FactoryTalk Linx and associated products contain a flaw in their file parsing mechanism, which fails to properly sanitize input from certain file types. This can lead to directory traversal attacks, enabling an attacker to potentially modify or expose sensitive data, or execute arbitrary code on the affected systems. Users are advised to apply necessary patches and monitoring to mitigate risks associated with these vulnerable versions.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FactoryTalk Linx, RSLinx Classic, Connected Components Workbench, ControlFLASH Plus, FactoryTalk Asset Centre, FactoryTalk Linx CommDTM, Studio 5000 Launcher, Studio 5000 Logix Designer software FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
