Vulnerability Details CVE-2020-12033
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.016
EPSS Ranking 80.8%
CVSS Severity
CVSS v3 Score 8.8
CVSS v2 Score 5.8
Products affected by CVE-2020-12033
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:-
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.51.00.8
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.61
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.71
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.73
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.74
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.80
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:2.90
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:6.10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:6.11.00
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:6.31.00
-
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:cpr9