PatchSiren cyber security CVE debrief
CVE-2024-37368 Rockwell Automation CVE debrief
A missing authentication vulnerability in Rockwell Automation FactoryTalk View SE v11.0 allows unauthenticated remote attackers to view HMI project data by sending a crafted packet to the server. The flaw stems from insufficient authentication verification when remote FTView systems request project access. CISA published advisory ICSA-24-165-18 on June 13, 2024, assigning CVSS 3.1 score 7.5 (HIGH). Rockwell Automation corrected this issue in FactoryTalk View SE V14.0. Organizations unable to upgrade should implement network segmentation and access controls per vendor guidance.
- Vendor
- Rockwell Automation
- Product
- FactoryTalk View SE
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-06-13
- Original CVE updated
- 2024-06-13
- Advisory published
- 2024-06-13
- Advisory updated
- 2024-06-13
Who should care
Industrial control system operators, OT security teams, manufacturing security engineers, critical infrastructure defenders, and organizations running Rockwell Automation FactoryTalk View SE for human-machine interface visualization in production environments.
Technical summary
The vulnerability exists in FactoryTalk View SE v11.0's remote project access functionality. A remote attacker with FTView can transmit a packet to a customer server to retrieve HMI project information without presenting valid credentials. The server fails to perform proper authentication verification before granting project view access. This represents a classic missing authentication control (CWE-306) in a client-server industrial protocol. The attack requires network access to the FactoryTalk View SE server but no user interaction or privileges. Successful exploitation exposes sensitive HMI project data including process configurations, potentially aiding further targeted attacks against industrial processes.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade FactoryTalk View SE to V14.0 or later to remediate the authentication bypass vulnerability.
- If immediate upgrade is not feasible, implement network segmentation to isolate HMI systems from untrusted networks.
- Apply IPsec-based access controls to restrict remote FTView system connectivity per Rockwell Automation security best practices.
- Review and enforce least-privilege access policies for industrial control system networks.
- Monitor network traffic for unauthorized FactoryTalk View SE project access attempts.
Evidence notes
CISA CSAF advisory ICSA-24-165-18 confirms the vulnerability affects FactoryTalk View SE v11.0, with correction in V14.0. CVSS 3.1 vector AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N indicates network-accessible, low-complexity attack with no privileges required, resulting in high confidentiality impact. No integrity or availability impact per scoring.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-37368 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-37368
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-37368 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37368
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-165-18.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-165-18
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.