Vulnerabilities > Rockwellautomation > Factorytalk View

DATE CVE VULNERABILITY TITLE RISK
2024-06-14 CVE-2024-37367 Improper Authentication vulnerability in Rockwellautomation Factorytalk View 12.0/13.0
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12.
network
low complexity
rockwellautomation CWE-287
7.5
2023-10-27 CVE-2023-46289 Improper Input Validation vulnerability in Rockwellautomation Factorytalk View
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline.
network
low complexity
rockwellautomation CWE-20
7.5
2023-09-12 CVE-2023-2071 Unrestricted Upload of File with Dangerous Type vulnerability in Rockwellautomation Factorytalk View 13.0
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.
network
low complexity
rockwellautomation CWE-434
critical
9.8
2022-02-24 CVE-2020-14480 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation Factorytalk View 10.0
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
local
low complexity
rockwellautomation CWE-312
5.5
2022-02-24 CVE-2020-14481 Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords.
local
low complexity
rockwellautomation CWE-326
7.8
2020-07-20 CVE-2020-12031 Out-of-bounds Write vulnerability in Rockwellautomation Factorytalk View
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution.
local
low complexity
rockwellautomation CWE-787
7.8
2020-07-20 CVE-2020-12028 Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions.
network
low complexity
rockwellautomation CWE-306
8.1
2020-07-20 CVE-2020-12027 Unspecified vulnerability in Rockwellautomation Factorytalk View
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system.
network
low complexity
rockwellautomation
4.3
2020-07-20 CVE-2020-12029 Unspecified vulnerability in Rockwellautomation Factorytalk View
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory.
local
low complexity
rockwellautomation
7.8