SOC status:Duty analyst on shift

UK Cyber Defence
VulnerabilityModified

CVE-2020-12025

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.

LOW 3.3EPSS 1.54%

Does this matter?

Lower severity and a low EPSS score (1.54%). Track it; it rarely justifies an emergency change on its own.

Description

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.

CVSS 3.1
3.3 LOWCVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N
EPSS
1.54% probability · 74th percentile
CISA KEV
Not listed
Weakness
CWE-611
Affected
rockwellautomation/studio 5000 logix designer
Source
ics-cert@hq.dhs.gov

References

Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.