PatchSiren cyber security CVE debrief
CVE-2025-24479 Rockwell Automation CVE debrief
CVE-2025-24479 is a high-severity local code execution issue in Rockwell Automation FactoryTalk View ME versions prior to 15.0, published by CISA on 2025-01-28. The advisory says the problem stems from a default Windows setting and can let a local user reach a command prompt as a higher-privileged user. Rockwell’s guidance is to upgrade to V15.0 or apply the listed patches, and to reduce exposure by limiting physical and network access to affected systems.
- Vendor
- Rockwell Automation
- Product
- FactoryTalk View ME
- CVSS
- HIGH 8.4
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-28
- Original CVE updated
- 2025-01-28
- Advisory published
- 2025-01-28
- Advisory updated
- 2025-01-28
Who should care
Organizations running Rockwell Automation FactoryTalk View ME in industrial or HMI environments, especially teams responsible for workstation hardening, local admin controls, physical access control, and patch management.
Technical summary
The advisory describes a local code execution vulnerability affecting Rockwell Automation FactoryTalk View ME versions prior to 15.0. CISA attributes the issue to a default Windows setting that allows access to the command prompt as a higher-privileged user. The published CVSS vector is AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H, reflecting a high-impact local issue rather than a remotely exploitable flaw.
Defensive priority
High. The issue is local, but it can still provide elevated command prompt access on affected systems. In ICS/HMI environments, local privilege escalation can materially increase operational risk, so upgrading or patching should be prioritized where exposure exists.
Recommended defensive actions
- Upgrade affected systems to FactoryTalk View ME V15.0.
- Apply the Rockwell patches referenced in the advisory (AID 1152309, 1152331, and 1152332) where applicable.
- Control physical access to affected systems.
- Protect network access to the device.
- Follow Rockwell Automation’s security best practices for industrial automation control systems.
- Use environment-specific prioritization methods such as CISA SSVC when determining remediation order.
Evidence notes
All statements above are drawn from the CISA CSAF advisory and the supplied advisory metadata. The source names Rockwell Automation FactoryTalk View ME as the affected product, with versions prior to 15.0 impacted. It states the issue is due to a default Windows setting and that the result is command prompt access as a higher-privileged user. The advisory also recommends upgrade to V15.0 or patches AID 1152309 / 1152331 / 1152332, plus physical and network access controls. No exploit technique, weaponization detail, or ransomware linkage is provided in the supplied corpus.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-24479 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-24479
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-24479 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-24479
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-028-03.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-028-03
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.