module

Rockwell FactoryTalk View SE SCADA Unauthenticated Remote Code Execution

Disclosed
Jun 22, 2020

Description

This module exploits a series of vulnerabilities to achieve unauthenticated remote code execution
on the Rockwell FactoryTalk View SE SCADA product as the IIS user.
The attack relies on the chaining of five separate vulnerabilities. The first vulnerability is an unauthenticated project copy request,
the second is a directory traversal, and the third is a race condition. In order to achieve full remote code execution on all
targets, two information leak vulnerabilities are also abused.
This exploit was used by the Flashback team (Pedro Ribeiro + Radek Domanski) in Pwn2Own Miami 2020 to win the EWS category.
Title
NEW

Explore Exposure Command

Confidently identify and prioritize exposures from endpoint to cloud with full attack surface visibility and threat-aware risk context.