#VU106093 Improper Neutralization of Special Elements in Output Used by a Downstream Component in 440G TLS-Z - CVE-2020-27212

 

#VU106093 Improper Neutralization of Special Elements in Output Used by a Downstream Component in 440G TLS-Z - CVE-2020-27212

Published: March 27, 2025


Vulnerability identifier: #VU106093
Vulnerability risk: Low
CVSSv4.0: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:U/U:Clear
CVE-ID: CVE-2020-27212
CWE-ID: CWE-74
Exploitation vector: Local access
Exploit availability: No public exploit available
Vulnerable software:
440G TLS-Z
Software vendor:
Rockwell Automation

Description

The vulnerability allows a local user to execute arbitrary code on the target system.

The vulnerability exists due to incorrect access controls. A local user can reverse protections that control access to the JTAG interface and take over the device.


Remediation

Cybersecurity Help is currently unaware of any official solution to address this vulnerability.

External links