CVE-2020-12025

LOW

Rockwell Automation Studio 5000 Logix Designer 32.00-32.02 - XML External Entity Injection

Title source: llm
STIX 2.1

Description

Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.

References (1)

Core 1
Core References
Third Party Advisory, US Government Resource x_refsource_misc
https://us-cert.cisa.gov/ics/advisories/icsa-20-191-02

Scores

CVSS v3 3.3
EPSS 0.0018
EPSS Percentile 39.0%
Attack Vector LOCAL
CVSS:3.1/AV:L/AC:L/PR:N/UI:R/S:U/C:L/I:N/A:N

Details

CWE
CWE-611
Status published
Products (3)
rockwellautomation/studio_5000_logix_designer 32.00
rockwellautomation/studio_5000_logix_designer 32.01
rockwellautomation/studio_5000_logix_designer 32.02
Published Jul 14, 2020
Tracked Since Feb 18, 2026