File System Exposure in FactoryTalk Linx and Related Products by Rockwell Automation
CVE-2020-12003
Key Information:
What is CVE-2020-12003?
An exposed API call in several Rockwell Automation products allows unauthorized users to provide files for processing without proper sanitation. This vulnerability could lead to file system traversal attacks, potentially exposing sensitive data stored on the local hard drive. If exploited, attackers could manipulate requests to gain access to critical information, highlighting the need for immediate security measures.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
FactoryTalk Linx, RSLinx Classic, Connected Components Workbench, ControlFLASH Plus, FactoryTalk Asset Centre, FactoryTalk Linx CommDTM, Studio 5000 Launcher, Studio 5000 Logix Designer software FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior
References
CVSS V3.1
Timeline
Vulnerability published
Vulnerability Reserved
