CVE-2020-14478: Rockwellautomation Factorytalk Services Platform
High severity, CVSS 7.1. EPSS: 0.3% chance of exploitation in the next 30 days.
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
Affected products
- Rockwellautomation Factorytalk Services Platform: up to and including 6.11.00
Published 2022-02-24. Last modified 2026-06-17.