In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
References
Link | Resource |
---|---|
https://www.us-cert.gov/ics/advisories/icsa-20-170-04 | Third Party Advisory US Government Resource |
Configurations
Information
Published : 2020-06-23 15:15
Updated : 2020-07-06 07:57
NVD link : CVE-2020-12033
Mitre link : CVE-2020-12033
JSON object : View
CWE
CWE-20
Improper Input Validation
Products Affected
rockwellautomation
- factorytalk_services_platform