Back

HIGH

Rockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication Restriction

Published Jun 14, 2024

Description

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.

Affected products

Remediation

Vendor solution

* Corrected in software version v14.0. * Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible.   

* It is recommended that users enforce proper access controls within the network and segment networks containing sensitive information using IPSec: https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1090456

* Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Jun 14, 2024
Updated Aug 2, 2024
Reserved Jun 6, 2024
CISA Vulnrichment
Updated Jun 17, 2024
NVD
Status Modified
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Rockwell
Published Jun 14, 2024
Updated Aug 2, 2024
Exploited since n/a
EUVD-2024-36615