PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-10944 Rockwell Automation CVE debrief

A high-severity remote code execution vulnerability in Rockwell Automation FactoryTalk Updater components, published 2024-11-14 and updated 2024-11-18. The flaw stems from improper input validation that could allow deployment of a malicious update agent when an attacker possesses high-level permissions. While the CVSS 3.1 score of 8.4 reflects significant impact potential, the attack requires high privileges and user interaction, limiting exploitability. Affected versions span FactoryTalk Updater Web Client 4.00.00 through 4.20.00, plus Client and Agent components below 4.20.00. Rockwell Automation has released version 4.20.00 as the definitive fix.

Vendor
Rockwell Automation
Product
FactoryTalk Updater - Web Client
CVSS
HIGH 8.4
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-14
Original CVE updated
2024-11-18
Advisory published
2024-11-14
Advisory updated
2024-11-18

Who should care

Industrial control system operators, OT security teams, manufacturing security engineers, and organizations running Rockwell Automation FactoryTalk Updater components in production environments

Technical summary

The vulnerability exists in FactoryTalk Updater's agent deployment mechanism due to insufficient input validation. An attacker with high privileges and user interaction capability could deploy a malicious update agent, achieving remote code execution with significant confidentiality, integrity, and availability impact. The attack surface is network-accessible but constrained by privilege requirements. Version 4.20.00 implements proper validation controls to prevent malicious agent deployment.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade FactoryTalk Updater Web Client, Client, and Agent components to version 4.20.00 or later
  • Restrict network and physical access to servers hosting FactoryTalk Updater
  • Perform database updates by clicking the 'Scan' button after patching
  • Review and implement Rockwell Automation security best practices for industrial control systems
  • Apply Stakeholder-Specific Vulnerability Categorization (SSVC) for environment-specific risk prioritization

Evidence notes

CVE published 2024-11-14; modified 2024-11-18. CISA CSAF advisory ICSA-24-319-14 issued same date with Update A on 2024-11-18 clarifying version information and correcting critical infrastructure sector classification. CVSS 3.1 vector: AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H. CVSS 4.0 vector also provided in source. Three product variants affected: Web Client (4.00.00–4.20.00), Client (<4.20.00), Agent (<4.20.00). Remediation requires update to version 4.20.00 across all components.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-10944 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-10944

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-10944 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10944

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-14.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-14

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.