Rewterz

Rewterz Threat Advisory – ICS: Phoenix Contact Automation Worx Software Suite

July 10, 2020
Rewterz

Rewterz Threat Advisory – CVE-2020-1647 – Juniper Junos OS Double free vulnerability

July 10, 2020

Rewterz Threat Advisory – CVE-2020-12025 – ICS: Rockwell Automation Logix Designer Studio 5000

Severity

Low

Analysis Summary

Logix Designer Studio 5000 use a third-party XML parser that natively accepts AML and RDF files from any external entity. If exploited successfully, an unauthenticated attacker might be able to create a malicious file, which, when scanned, could lead to the disclosure of hostname information or other program resources.

Impact

Information disclosure

Affected Vendors

Rockwell Automation

Affected Products

  • Logix Designer Studio 5000 Versions 32.00
  • Logix Designer Studio 5000 Versions 32.01
  • Logix Designer Studio 5000 Versions 32.02

Remediation

Refer to ICS advisory for the complete list of affected products and respective patches.

https://us-cert.cisa.gov/ics/advisories/icsa-20-191-02

Reading this advisory was a good start.

Make it a habit.

Rewterz publishes threat advisories ahead of mainstream cybersecurity media, informed by an AI-Native Autonomous SOC that sees regional threat actor activity in real time. Subscribe to receive each new advisory as it publishes, plus a monthly Middle East threat landscape brief drawn from our own SOC telemetry. For teams evaluating their detection coverage, a 30-minute consultation with a senior analyst is also available, at your pace, when you're ready.