Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-50513 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.
Fixes

Solution

* Install the patch that remediates the issue: BF29581 - Patch: External Service Interaction (HTTP), FactoryTalk View SE 11.0, 12.0 13.0 https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140243 .


Workaround

No workaround given by the vendor.

History

Tue, 04 Mar 2025 03:45:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-02-27T20:39:04.320Z

Reserved: 2023-10-20T18:01:46.095Z

Link: CVE-2023-46289

cve-icon Vulnrichment

Updated: 2024-08-02T20:45:40.738Z

cve-icon NVD

Status : Modified

Published: 2023-10-27T19:15:41.493

Modified: 2024-11-21T08:28:14.307

Link: CVE-2023-46289

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.