Vulnerabilities > Rockwellautomation > Factorytalk View
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-11-12 | CVE-2024-37365 | Unspecified vulnerability in Rockwellautomation Factorytalk View 14.0 A remote code execution vulnerability exists in the affected product. | 7.8 |
2024-09-12 | CVE-2024-45824 | Command Injection vulnerability in Rockwellautomation Factorytalk View 12.0/13.0 CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. | 9.8 |
2024-08-14 | CVE-2024-7513 | Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Factorytalk View 13.0/14.0 CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. | 8.8 |
2024-06-14 | CVE-2024-37369 | Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Factorytalk View 12.0/13.0 A privilege escalation vulnerability exists in the affected product. | 8.8 |
2024-06-14 | CVE-2024-37367 | Improper Authentication vulnerability in Rockwellautomation Factorytalk View 12.0/13.0 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. | 7.5 |
2024-06-14 | CVE-2024-37368 | Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View 11.0/12.0/13.0 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. | 7.5 |
2024-05-16 | CVE-2024-4609 | SQL Injection vulnerability in Rockwellautomation Factorytalk View 10.0 A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. | 9.8 |
2023-10-27 | CVE-2023-46289 | Improper Input Validation vulnerability in Rockwellautomation Factorytalk View Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. | 7.5 |
2023-09-12 | CVE-2023-2071 | Unrestricted Upload of File with Dangerous Type vulnerability in Rockwellautomation Factorytalk View 13.0 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. | 9.8 |
2022-02-24 | CVE-2020-14480 | Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation Factorytalk View 10.0 Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials. | 5.5 |