CVE-2020-14481 Vulnerability Details

  /     /     /  

CVE-2020-14481 Metadata Quick Info

CVE Published: 24/02/2022 | CVE Updated: 16/09/2024 | CVE Year: 2020
Source: icscert | Vendor: Rockwell Automation | Product: FactoryTalk View SE
Status : PUBLISHED

CVE-2020-14481 Description

The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.

Metrics

CVSS Version: 3.1 | Base Score: n/a
Vector: n/a

l➤ Exploitability Metrics:
    Attack Vector (AV)*
    Attack Complexity (AC)*
    Privileges Required (PR)*
    User Interaction (UI)*
    Scope (S)*

l➤ Impact Metrics:
    Confidentiality Impact (C)*
    Integrity Impact (I)*
    Availability Impact (A)*

Weakness Enumeration (CWE)

CWE-ID: CWE-261
CWE Name: CWE-261 Weak Cryptography for Passwords
Source: Rockwell Automation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID:
CAPEC Description:


Source: NVD (National Vulnerability Database).