← Vulnerability feed

Vulnerability record · CVE-2020-12034 · published 20 May 2020

CVE-2020-12034: Rockwellautomation eds subsystem sql injection vulnerability

Rockwellautomation · Eds Subsystem

Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is vulnerable.The EDS subsystem does not provide adequate input sanitation, which may allow an attacker to craft specialized EDS files to inject SQL queries and manipulate the database storing the EDS files. This can lead to denial-of-service conditions.

8.2 CVSS 3.1 High EPSS 1.3% · top 31.5% CWE-89 · SQL injection
8.2CVSS 3.1 base score, v2 4.8
1.3%EPSS exploitation probability, 30 days
NoNot in CISA KEV
5Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is vulnerable.The EDS subsystem does not provide adequate input sanitation, which may allow an attacker to craft specialized EDS files to inject SQL queries and manipulate the database storing the EDS files. This can lead to denial-of-service conditions.

CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:C/C:N/I:L/A:H

Affected products

5 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

LinkTags
https://www.us-cert.gov/ics/advisories/icsa-20-140-01 MitigationPatchThird Party AdvisoryUS Government Resource
https://www.us-cert.gov/ics/advisories/icsa-20-140-01 MitigationPatchThird Party AdvisoryUS Government Resource

Track CVE-2020-12034 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2021-22681Rockwell Logix Designer authentication bypass via weak key verificationRockwell Automation Studio 5000 Logix Designer (v21+) and RSLogix 5000 (v16-20) rely on a key to verify that Logix controllers are talking to genuine…KEVEPSS 64%analysed10.0CVE-2012-4715Rockwellautomation rslinx enterprise memory buffer overflow vulnerabilityBuffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and C…EPSS 7.8%9.8CVE-2019-6553Rockwell RSLinx Classic stack buffer overflow via Forward Open requestRockwell Automation RSLinx Classic 4.10.00 and prior contains an input validation flaw in a DLL where data from a Forward Open service request is cop…EPSS 66%analysed9.8CVE-2018-14829Rockwellautomation rslinx stack-based buffer overflow vulnerabilityRockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed C…EPSS 16%9.3CVE-2011-2530Rockwellautomation rslinx memory buffer overflow vulnerabilityBuffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.…EPSS 7.6%7.5CVE-2020-13573Rockwellautomation rslinx memory buffer overflow vulnerabilityA denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A speci…EPSS 3.4%7.5CVE-2013-2805Rockwellautomation rslinx enterprise out-of-bounds read vulnerabilityRockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…EPSS 3.9%7.5CVE-2013-2806Rockwellautomation rslinx enterprise integer overflow vulnerabilityRockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…EPSS 3.9%

Source: NIST National Vulnerability Database (record CVE-2020-12034), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.