SQL injection in Rockwell Automation products - CVE-2020-12034
Published: May 20, 2020
EDS Subsystem
RSLinx Classic
FactoryTalk Linx
RSNetWorx software
Studio 5000 Logix Designer
Rockwell Automation
Description
The vulnerability allows a remote attacker to execute arbitrary SQL queries in database.
The vulnerability exists due to insufficient sanitization of user-supplied data. A remote attacker on the local network can send a specially crafted EDS file to the affected application and manipulate the database storing the EDS files, leading to denial-of-service conditions.