EDS Subsystem Vulnerabilities Expose OT Assets to Malicious File Delivery
ID: 9e28ffed-18a1-54ce-bc1e-c087fb4f8bae
STIX ID: report--9e28ffed-18a1-54ce-bc1e-c087fb4f8bae
Feed Name: Claroty Team82
Claroty (Team82) disclosed vulnerabilities in the Rockwell Automation EDS Subsystem (CVE-2020-12038, CVE-2020-12034) affecting FactoryTalk Linx, RSLinx Classic, RSNetWorx, and Studio 5000 Logix Designer; crafted malicious EDS files presented via device discovery can write files to disk (including startup locations) enabling code execution on restart or crash the EDS parser to cause denial-of-service. The report includes a proof-of-concept demonstration, notes no known in-the-wild exploitation, and advises applying vendor patches and network mitigations (segmentation, blocking EtherNet/IP/CIP ports, and using secure remote access).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
