PT-2024-27502 · Rockwell Automation · Rockwell Automation Factorytalk View Machine Edition

Published

2024-11-12

·

Updated

2024-11-12

·

CVE-2024-37365

CVSS v3.1

7.8

High

VectorAV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation FactoryTalk View Machine Edition V14
Description A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory, allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by changing the macro to execute arbitrary code.
Recommendations For Rockwell Automation FactoryTalk View Machine Edition V14, patch immediately and validate input to prevent potential system compromise. As a temporary workaround, consider restricting access to the public directory to minimize the risk of exploitation. Avoid using macros that could potentially execute arbitrary code until the issue is resolved.

Fix

RCE

Weakness Enumeration

Related Identifiers

CVE-2024-37365

Affected Products

Rockwell Automation Factorytalk View Machine Edition