ID

VAR-202006-1966


TITLE

(Pwn2Own) Rockwell Automation FactoryTalk View SE RegisterEDSFiles Directory Traversal Remote Code Execution Vulnerability

Trust: 0.7

sources: ZDI: ZDI-20-734

DESCRIPTION

This vulnerability allows remote attackers to create arbitrary files on affected installations of Rockwell Automation FactoryTalk View SE. Authentication is not required to exploit this vulnerability.The specific flaw exists within the handling of fileName parameter in the RegisterEDSFiles tag. The issue results in the lack of proper validation of a user-supplied path prior to using it in file operations. An attacker can leverage this vulnerability to execute code in the context of SYSTEM.

Trust: 0.7

sources: ZDI: ZDI-20-734

AFFECTED PRODUCTS

vendor:rockwell automationmodel:factorytalk view sescope: - version: -

Trust: 0.7

sources: ZDI: ZDI-20-734

CVSS

SEVERITY

CVSSV2

CVSSV3

ZDI: ZDI-20-734
value: CRITICAL

Trust: 0.7

ZDI: ZDI-20-734
baseSeverity: CRITICAL
baseScore: 9.8
vectorString: AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
attackVector: NETWORK
attackComplexity: LOW
privilegesRequired: NONE
userInteraction: NONE
scope: UNCHANGED
confidentialityImpact: HIGH
integrityImpact: HIGH
availabilityImpact: HIGH
exploitabilityScore: 3.9
impactScore: 5.9
version: 3.0

Trust: 0.7

sources: ZDI: ZDI-20-734

PATCH

title:Rockwell Automation has issued an update to correct this vulnerability.url:https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126945

Trust: 0.7

sources: ZDI: ZDI-20-734

EXTERNAL IDS

db:ZDI_CANid:ZDI-CAN-10298

Trust: 0.7

db:ZDIid:ZDI-20-734

Trust: 0.7

sources: ZDI: ZDI-20-734

REFERENCES

url:https://rockwellautomation.custhelp.com/app/answers/detail/a_id/1126945

Trust: 0.7

sources: ZDI: ZDI-20-734

CREDITS

Sharon Brizinov, Amir Preminger of Claroty Research

Trust: 0.7

sources: ZDI: ZDI-20-734

SOURCES

db:ZDIid:ZDI-20-734

LAST UPDATE DATE

2022-05-17T01:46:20.239000+00:00


SOURCES UPDATE DATE

db:ZDIid:ZDI-20-734date:2020-06-22T00:00:00

SOURCES RELEASE DATE

db:ZDIid:ZDI-20-734date:2020-06-22T00:00:00