PT-2024-3630 · Rockwell Automation · Factorytalk View Se

Published

2024-05-16

·

Updated

2025-01-30

·

CVE-2024-4609

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation FactoryTalk View SE Datalog function
Description A threat actor could inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. This could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.
Recommendations To resolve the issue, ensure that the SQL database has proper authentication in place and protect legitimate credentials from being stolen. Implementing secure authentication mechanisms for the SQL database will help prevent malicious SQL statement injection.

Fix

SQL injection

RCE

Weakness Enumeration

Related Identifiers

BDU:2024-03951
CVE-2024-4609

Affected Products

Factorytalk View Se