HIGH🇬🇧 English

CVE-2020-14481

CVSS 7.8v3.1pub. 2022-02-24upd. 2025-04-17

The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.

oryginał EN
CVSS Vector
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
  • Rockwellautomation Factorytalk View

    APP
    Rockwellautomation
    10.0≤ 9.0
🔵
ZWERYFIKUJ U PRODUCENTA
Brak jednoznacznych danych o patchu. Sprawdź referencje od producenta.
CWE
Referencje

Powiązane podatności

CVE-2024-45824CRITICAL9.2PL ✓ten sam produkt

RCE w Rockwell Automation FactoryTalk View — łańcuch path traversal, command injection i XSS

CVE-2023-2071CRITICAL9.8PL ✓ten sam produkt

RCE bez uwierzytelnienia w Rockwell Automation FactoryTalk View na PanelView Plus

CVE-2020-12029CRITICAL9.0PL ✓ten sam produkt

RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików

CVE-2025-9063HIGH7.0ten sam produkt

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...

CVE-2025-9064HIGH8.7ten sam produkt

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attac...