A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.
History

Fri, 16 Aug 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation factorytalk View
CPEs cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation factorytalk View
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2024-06-14T14:17:54.951Z

Updated: 2024-08-02T03:50:56.151Z

Reserved: 2024-06-06T20:18:27.551Z

Link: CVE-2024-37367

cve-icon Vulnrichment

Updated: 2024-06-17T15:37:21.571Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T15:15:51.940

Modified: 2024-11-21T09:23:43.120

Link: CVE-2024-37367

cve-icon Redhat

No data.