A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Factorytalk View
APPRockwellautomation≤ 15.0
Related vulnerabilities
RCE w Rockwell Automation FactoryTalk View — łańcuch path traversal, command injection i XSS
RCE bez uwierzytelnienia w Rockwell Automation FactoryTalk View na PanelView Plus
RCE w Rockwell Automation FactoryTalk View SE — brak walidacji nazw plików
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX co...
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save p...