Rockwell Automation FactoryTalk® View Site Edition Vulnerable to Improper Input Validation
CVE-2023-46289
7.5HIGH
Key Information:
- Vendor
- Rockwell Automation
- Vendor
- CVE Published:
- 27 October 2023
Summary
Rockwell Automation's FactoryTalk View Site Edition exhibits insufficient validation of user input, which can be exploited by threat actors to send harmful data. This vulnerability has the potential to disrupt system availability, leading to a denial-of-service condition. In the event of exploitation, the affected system may require a restart for recovery, which poses significant risks to operational continuity.
Affected Version(s)
FactoryTalk® View Site Edition versions 11.0-13.0
References
CVSS V3.1
Score:
7.5
Severity:
HIGH
Confidentiality:
None
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Privileges Required:
None
User Interaction:
None
Scope:
Unchanged
Timeline
Vulnerability published
Vulnerability Reserved
Credit
This vulnerability was found internally during routine testing.