CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-45824

CVSS 9.2v4.0pub. 2024-09-12upd. 2025-01-31

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.

🤖 AI Analysis
How it works

The vulnerability arises from the chaining of three separate weaknesses: path traversal, command injection and XSS. An attacker can remotely trigger this chain of vulnerabilities, which in effect leads to full, unauthenticated execution of arbitrary code on the vulnerable system. No user interaction is required to carry out the attack.

Impact

Attacker gains full control over the vulnerable system — can execute arbitrary code remotely without authentication, threatening confidentiality, integrity and availability of data and system.

Mitigation & patch

Apply patches available from the manufacturer according to references — detailed information about fixes is available at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html

Who is affected

Rockwell Automation FactoryTalk View — versions indicated in the manufacturer's references (advisory SD1696)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rockwellautomation Factorytalk View

    APP
    Rockwellautomation
    12.0 – 14.0
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
RCEXSSPath Traversal
CWE
References

Related vulnerabilities

CVE-2023-2071CRITICAL9.8PL ✓same product

RCE bez uwierzytelnienia w Rockwell Automation FactoryTalk View na PanelView Plus

CVE-2020-12029CRITICAL9.0PL ✓same product

RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików

CVE-2025-9063HIGH7.0same product

An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...

CVE-2025-9064HIGH8.7same product

A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attac...

CVE-2024-37365HIGH7.0same product

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save p...