Vulnerabilities > Rockwellautomation > Factorytalk View > High
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2024-08-14 | CVE-2024-7513 | Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Factorytalk View 13.0/14.0 CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. | 8.8 |
2024-06-14 | CVE-2024-37369 | Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Factorytalk View 12.0/13.0 A privilege escalation vulnerability exists in the affected product. | 8.8 |
2024-06-14 | CVE-2024-37367 | Improper Authentication vulnerability in Rockwellautomation Factorytalk View 12.0/13.0 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. | 7.5 |
2024-06-14 | CVE-2024-37368 | Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View 11.0/12.0/13.0 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. | 7.5 |
2023-10-27 | CVE-2023-46289 | Improper Input Validation vulnerability in Rockwellautomation Factorytalk View Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. | 7.5 |
2022-02-24 | CVE-2020-14481 | Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0 The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. | 7.8 |
2020-07-20 | CVE-2020-12031 | Out-of-bounds Write vulnerability in Rockwellautomation Factorytalk View In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. | 7.8 |
2020-07-20 | CVE-2020-12028 | Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. | 8.1 |
2020-07-20 | CVE-2020-12029 | Unspecified vulnerability in Rockwellautomation Factorytalk View All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. | 7.8 |