Rockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication Restriction
Published Jun 14, 2024
8.2
HIGHCVSS 4.0
EPSS 0.50%
Description
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.
Affected products
-
- Version v12StatusaffectedConstraints-
- Version
Default status is the baseline for the product, each version can override it (e.g. patched versions marked unaffected).
| Vendor | Product | Default status | Versions | ||||||
|---|---|---|---|---|---|---|---|---|---|
| Rockwell Automation | FactoryTalk® View SE | unaffected |
|
- ≥ 12.0 · < 14.0
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
* Corrected in software version v14.0. * Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible.
* It is recommended that users enforce proper access controls within the network and segment networks containing sensitive information using IPSec: https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1090456
* Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-36615 Advisory
- https://https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1675.html Broken Link
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2024-36615 | Advisory | |
| https://https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1675.html | Broken Link |
Change history (0)
No recorded changes yet.