A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.
Metrics
Affected Vendors & Products
Source | ID | Title |
---|---|---|
![]() |
EUVD-2024-48421 | CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions. |
Solution
Upgrade to v15.0
Workaround
Customers using the affected software are encouraged to apply security best practices, if possible. * Remove “Everyone” user group from read and write privileges by changing the FactoryTalk® View SE project folder permissions using the help guide. Detailed instructions are below. * Open FactoryTalk® View Studio -> Help -> FactoryTalk® View SE Help. In the file -> Security -> “HMI projects folder”
Fri, 31 Jan 2025 15:45:00 +0000
Type | Values Removed | Values Added |
---|---|---|
CPEs | cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:* | |
Metrics |
cvssV3_1
|
Wed, 14 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rockwellautomation
Rockwellautomation factorytalk View |
|
CPEs | cpe:2.3:a:rockwellautomation:factorytalk_view:13.0:*:*:*:se:*:*:* | |
Vendors & Products |
Rockwellautomation
Rockwellautomation factorytalk View |
|
Metrics |
ssvc
|
Wed, 14 Aug 2024 20:00:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions. | |
Title | Rockwell Automation FactoryTalk® View Site Edition Code Execution Vulnerability via File Permissions | |
Weaknesses | CWE-732 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2025-08-15T13:03:12.526Z
Reserved: 2024-08-05T20:18:13.759Z
Link: CVE-2024-7513

Updated: 2024-08-14T20:16:19.702Z

Status : Analyzed
Published: 2024-08-14T20:15:13.013
Modified: 2025-01-31T15:25:24.030
Link: CVE-2024-7513

No data.

No data.