CVE-2020-14481
Severity CVSS v4.0:
Pending analysis
Type:
Unavailable / Other
Publication date:
24/02/2022
Last modified:
17/04/2025
Description
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the user’s operating system and certain components of FactoryTalk View SE.
Impact
Base Score 3.x
7.80
Severity 3.x
HIGH
Base Score 2.0
2.10
Severity 2.0
LOW
Vulnerable products and versions
CPE | From | Up to |
---|---|---|
cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:* | 9.0 (including) | |
cpe:2.3:a:rockwellautomation:factorytalk_view:10.0:*:*:*:se:*:*:* |
To consult the complete list of CPE names with products and versions, see this page