PT-2024-3630 · Rockwell Automation · Factorytalk View Se
Published
2024-05-16
·
Updated
2025-01-30
·
CVE-2024-4609
CVSS v3.1
9.8
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation FactoryTalk View SE Datalog function
Description
A threat actor could inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. This could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.
Recommendations
To resolve the issue, ensure that the SQL database has proper authentication in place and protect legitimate credentials from being stolen. Implementing secure authentication mechanisms for the SQL database will help prevent malicious SQL statement injection.
Fix
SQL injection
RCE
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Factorytalk View Se