PT-2011-4207 · Rockwell Automation · Factorytalk Diagnostics Viewer
Published
2011-07-28
·
Updated
2011-08-12
·
CVE-2011-2957
CVSS v2.0
6.9
Medium
| Vector | AV:L/AC:M/Au:N/C:C/I:C/A:C |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation FactoryTalk Diagnostics Viewer versions prior to V2.30.00 (CPR9 SR3)
Description
The issue allows local users to execute arbitrary code via a crafted FactoryTalk Diagnostics Viewer (.ftd) configuration file, which triggers memory corruption.
Recommendations
For versions prior to V2.30.00 (CPR9 SR3), update to V2.30.00 (CPR9 SR3) or later to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Factorytalk Diagnostics Viewer