CRITICAL🇵🇱 Wersja polska

CVE-2023-2071

CVSS 9.8v3.1pub. 2023-09-12upd. 2024-11-21

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
  • Rockwellautomation Factorytalk View

    APP
    Rockwellautomation
    ≤ 13.0
  • Rockwellautomation Panelview Plus

    HW
    Rockwellautomation
    all versions
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth Bypass
CWE
References

Related vulnerabilities

CVE-2024-45824CRITICAL9.2PL ✓same product

RCE w Rockwell Automation FactoryTalk View — łańcuch path traversal, command injection i XSS

CVE-2020-12029CRITICAL9.0PL ✓same product

RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików

CVE-2025-9063HIGH7.0same product

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...

CVE-2025-9064HIGH8.7same product

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attac...

CVE-2024-37365HIGH7.0same product

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save p...