A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.

Project Subscriptions

Vendors Products
Rockwellautomation Subscribe
Factorytalk View Subscribe
Advisories
Source ID Title
EUVD EUVD EUVD-2024-36615 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.
Fixes

Solution

* Corrected in software version v14.0. * Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible.    * It is recommended that users enforce proper access controls within the network and segment networks containing sensitive information using IPSec: https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1090456 * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight


Workaround

No workaround given by the vendor.

History

Fri, 16 Aug 2024 19:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation factorytalk View
CPEs cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation factorytalk View
Metrics cvssV3_1

{'score': 7.5, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N'}


Projects

Sign in to view the affected projects.

cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2024-08-02T03:50:56.151Z

Reserved: 2024-06-06T20:18:27.551Z

Link: CVE-2024-37367

cve-icon Vulnrichment

Updated: 2024-06-17T15:37:21.571Z

cve-icon NVD

Status : Modified

Published: 2024-06-14T15:15:51.940

Modified: 2024-11-21T09:23:43.120

Link: CVE-2024-37367

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.

Weaknesses