PatchSiren cyber security CVE debrief
CVE-2024-10944 Rockwell Automation CVE debrief
A high-severity remote code execution vulnerability in Rockwell Automation FactoryTalk Updater components, published 2024-11-14 and updated 2024-11-18. The flaw stems from improper input validation that could allow deployment of a malicious update agent when an attacker possesses high-level permissions. While the CVSS 3.1 score of 8.4 reflects significant impact potential, the attack requires high privileges and user interaction, limiting exploitability. Affected versions span FactoryTalk Updater Web Client 4.00.00 through 4.20.00, plus Client and Agent components below 4.20.00. Rockwell Automation has released version 4.20.00 as the definitive fix.
- Vendor
- Rockwell Automation
- Product
- FactoryTalk Updater - Web Client
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-18
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-18
Who should care
Industrial control system operators, OT security teams, manufacturing security engineers, and organizations running Rockwell Automation FactoryTalk Updater components in production environments
Technical summary
The vulnerability exists in FactoryTalk Updater's agent deployment mechanism due to insufficient input validation. An attacker with high privileges and user interaction capability could deploy a malicious update agent, achieving remote code execution with significant confidentiality, integrity, and availability impact. The attack surface is network-accessible but constrained by privilege requirements. Version 4.20.00 implements proper validation controls to prevent malicious agent deployment.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade FactoryTalk Updater Web Client, Client, and Agent components to version 4.20.00 or later
- Restrict network and physical access to servers hosting FactoryTalk Updater
- Perform database updates by clicking the 'Scan' button after patching
- Review and implement Rockwell Automation security best practices for industrial control systems
- Apply Stakeholder-Specific Vulnerability Categorization (SSVC) for environment-specific risk prioritization
Evidence notes
CVE published 2024-11-14; modified 2024-11-18. CISA CSAF advisory ICSA-24-319-14 issued same date with Update A on 2024-11-18 clarifying version information and correcting critical infrastructure sector classification. CVSS 3.1 vector: AV:N/AC:L/PR:H/UI:R/S:C/C:H/I:H/A:H. CVSS 4.0 vector also provided in source. Three product variants affected: Web Client (4.00.00–4.20.00), Client (<4.20.00), Agent (<4.20.00). Remediation requires update to version 4.20.00 across all components.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-10944 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-10944
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-10944 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-10944
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-14.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-14
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.