Improper Input Validation in Rockwell Automation FactoryTalk Alarms and Events
CVE-2017-14022

7.5HIGH

What is CVE-2017-14022?

An input validation flaw was identified in Rockwell Automation's FactoryTalk Alarms and Events software, versions up to 2.90. This vulnerability allows an unauthenticated attacker with remote network access to exploit the service by sending specially crafted packets to Port 403/TCP, targeting the history archiver service. As a result, the service may become unresponsive or terminate unexpectedly, thereby potentially allowing for further attacks within the network.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.

Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.

Affected Version(s)

Rockwell Automation FactoryTalk Alarms and Events Rockwell Automation FactoryTalk Alarms and Events

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.