Rockwell Automation FactoryTalk® View Site Edition Vulnerable to Improper Input Validation
CVE-2023-46289

7.5HIGH

Key Information:

Vendor
CVE Published:
27 October 2023

Summary

Rockwell Automation's FactoryTalk View Site Edition exhibits insufficient validation of user input, which can be exploited by threat actors to send harmful data. This vulnerability has the potential to disrupt system availability, leading to a denial-of-service condition. In the event of exploitation, the affected system may require a restart for recovery, which poses significant risks to operational continuity.

Affected Version(s)

FactoryTalk® View Site Edition versions 11.0-13.0

References

CVSS V3.1

Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged

Timeline

  • Vulnerability published

  • Vulnerability Reserved

Credit

This vulnerability was found internally during routine testing.
.