CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.
The vulnerability arises from the chaining of three separate weaknesses: path traversal, command injection and XSS. An attacker can remotely trigger this chain of vulnerabilities, which in effect leads to full, unauthenticated execution of arbitrary code on the vulnerable system. No user interaction is required to carry out the attack.
Attacker gains full control over the vulnerable system — can execute arbitrary code remotely without authentication, threatening confidentiality, integrity and availability of data and system.
Apply patches available from the manufacturer according to references — detailed information about fixes is available at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html
Rockwell Automation FactoryTalk View — versions indicated in the manufacturer's references (advisory SD1696)
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Factorytalk View
APPRockwellautomation12.0 – 14.0
Related vulnerabilities
RCE bez uwierzytelnienia w Rockwell Automation FactoryTalk View na PanelView Plus
RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attac...
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save p...