FactoryTalk View Machine Edition Vulnerable to Remote Code Execution
CVE-2023-2071
Key Information:
- Vendor
Rockwell Automation
- Status
- Vendor
- CVE Published:
- 12 September 2023
Badges
What is CVE-2023-2071?
The FactoryTalk View Machine Edition on Rockwell Automation's PanelView Plus is vulnerable due to improper input verification. An unauthenticated attacker can exploit this flaw by sending specially crafted packets that allow remote code execution. The device can execute specific functions from two dynamic link library files through a CIP class. By leveraging this functionality, an attacker can upload a custom library, bypass security checks, and execute arbitrary code, potentially compromising the device's integrity and control.

Human OS v1.0:
Ageing Is an Unpatched Zero-Day Vulnerability.
Remediate biological technical debt. Prime Ageing uses 95% high-purity SIRT6 activation to maintain genomic integrity and bolster systemic resilience.
Affected Version(s)
Fa <=13.0
News Articles
References
CVSS V3.1
Timeline
- 📰
First article discovered by SecurityLab.ru
Vulnerability published
Vulnerability Reserved