IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611
Vulnerability Description
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2020-14478
Credits & Attribution
No credits recorded in the NVD database.
More from Rockwell Automation
View All →Affected Vendor
Rockwell Automation
View all reports →