Vulnerabilities > CVE-2020-12025 - XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02

047910
CVSS 3.3 - LOW
Attack vector
LOCAL
Attack complexity
LOW
Privileges required
NONE
Confidentiality impact
LOW
Integrity impact
NONE
Availability impact
NONE
local
low complexity
rockwellautomation
CWE-611

Summary

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.