These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.
Rockwell Automation FactoryTalk System Services and FactoryTalk Policy Manager version 6.40 insecurely stores private keys with read and execute permissions granted to the Windows 'Everyone' group. These keys are used to generate digital certificates and pre-shared keys for CIP Security and OPC UA communications. A malicious user with local access to the affected machine could obtain these private keys an [truncated]
CVE-2024-6236 is a medium-severity information exposure vulnerability in Rockwell Automation FactoryTalk System Services and FactoryTalk Policy Manager version 6.40. Published on July 11, 2024, the flaw stems from insufficient permissions on backup folders used during backup or restore operations. When these processes run, sensitive materials—including private keys, passwords, pre-shared keys, and databas [truncated]
A vulnerability in Rockwell Automation ThinManager ThinServer allows unauthenticated remote attackers to cause denial-of-service conditions by sending malicious messages to a monitor thread. The flaw stems from improper input validation and affects multiple versions of ThinServer from 11.1.0 through 13.1.0. Rockwell Automation has released corrected versions for all affected branches.
CVE-2024-5989 is a critical vulnerability in Rockwell Automation ThinManager ThinServer, published on July 11, 2024. The flaw stems from improper input validation, allowing an unauthenticated attacker to send a malicious message that triggers SQL injection and results in remote code execution on the affected device. The vulnerability carries a CVSS 3.1 score of 9.8 (Critical), reflecting network-based att [truncated]
A critical remote code execution vulnerability in Rockwell Automation ThinManager ThinServer allows unauthenticated attackers to execute arbitrary code by sending malicious messages due to improper input validation. The vulnerability affects multiple versions from 11.1.0 through 13.2.0 and was disclosed by CISA on July 11, 2024.
A privilege escalation vulnerability in Rockwell Automation FactoryTalk View SE allows low-privilege users to edit scripts while bypassing Access Control Lists (ACLs), potentially enabling further system access. The vulnerability affects FactoryTalk View SE version 12.0 and was corrected in version 14.0. The issue was published by CISA on June 13, 2024.
A missing authentication vulnerability in Rockwell Automation FactoryTalk View SE v11.0 allows unauthenticated remote attackers to view HMI project data by sending a crafted packet to the server. The flaw stems from insufficient authentication verification when remote FTView systems request project access. CISA published advisory ICSA-24-165-18 on June 13, 2024, assigning CVSS 3.1 score 7.5 (HIGH). Rockwe [truncated]
A user authentication vulnerability in Rockwell Automation FactoryTalk View SE allows remote, unauthenticated access to HMI projects. A remote attacker with FTView can send a crafted packet to a customer's server to view an HMI project without proper authentication verification. The vulnerability affects FactoryTalk View SE version 12.0. Rockwell Automation has corrected this issue in version 14.0 and later.
A vulnerability in Rockwell Automation ControlLogix, GuardLogix, and CompactLogix controllers allows an unauthenticated attacker on the same network to trigger a major nonrecoverable fault (MNRF/Assert) by sending abnormal packets to the mDNS port (UDP 5353). Successful exploitation causes complete loss of device availability. The vulnerability affects six product lines across multiple firmware versions, [truncated]
A SQL injection vulnerability in Rockwell Automation FactoryTalk View SE's Datalog function allows authenticated threat actors to inject malicious SQL statements when databases lack authentication or credentials are compromised. The flaw affects HMI design-time operations only, not runtime. Successful exploitation enables information disclosure, data modification, and deletion in remote databases. The vul [truncated]
An unquoted executable path vulnerability exists in Rockwell Automation FactoryTalk Remote Access (FTRA) versions ≤v13.5.0.174. The vulnerability occurs during installation when the executable path is not properly quoted, potentially allowing a threat actor with administrative privileges to achieve remote code execution as SYSTEM by placing a malicious executable in the unquoted path. This vulnerability r [truncated]
CVE-2024-3493 is a high-severity vulnerability (CVSS 8.6) affecting multiple Rockwell Automation industrial control system products. A specific malformed fragmented packet can trigger a major nonrecoverable fault (MNRF), causing affected devices to become unavailable until manually restarted. This condition may result in loss of view and/or control of connected industrial devices. The vulnerability was in [truncated]
A high-severity input validation vulnerability in Rockwell Automation's 5015-AENFTXT industrial adapter allows remote attackers to trigger a Major Non-Recoverable Fault (MNRF) via malformed PTP packets, requiring manual device restart to restore availability. The vulnerability was disclosed by CISA on April 11, 2024, with an advisory update on April 25, 2024 expanding affected product versions and mitigations.
CVE-2023-34348 is a high-severity denial-of-service vulnerability affecting Rockwell Automation FactoryTalk Historian SE versions 9.0 and earlier. The vulnerability resides in the underlying AVEVA PI Server component, specifically the PI Message Subsystem. An unauthenticated remote attacker can exploit this flaw to crash the PI Message Subsystem, rendering FactoryTalk Historian SE unavailable and requirin [truncated]
CVE-2023-31274 is a high-severity vulnerability in Rockwell Automation FactoryTalk Historian SE, published on 2024-05-09. The product incorporates the AVEVA PI Server, which contains a memory exhaustion flaw in its PI Message Subsystem. An unauthenticated remote attacker can exploit this vulnerability to trigger a partial denial-of-service condition by consuming available memory. Successful exploitation r [truncated]
A NULL pointer dereference vulnerability exists in GNU Tar versions before 1.32, specifically in the pax_decode_header function within sparse.c. This vulnerability is present in Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The flaw occurs when parsing archives containing malformed extended headers, which can trigger a denial-of-service condition requiring a software restart to r [truncated]
CVE-2019-18276 is a HIGH severity vulnerability (CVSS 7.8) affecting Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The vulnerability stems from the product's use of GNU Bash through 5.0 patch 11, specifically in the disable_priv_mode function within shell.c. A threat actor with existing shell command execution capabilities can leverage the 'enable -f' mechanism for runtime loadin [truncated]
A heap-based buffer overflow vulnerability exists in Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The vulnerability stems from the product's use of LZ4 compression library versions prior to 1.9.2, specifically affecting the LZ4_compress_fast function when processing large inputs. The flaw, related to LZ4_compress_destSize, can result in data corruption and, if exploited, enable [truncated]
Rockwell Automation KEPServerEX versions 6.0 through 6.14.263 are affected by a denial-of-service weakness in OPC UA message decoding. According to the CISA advisory, the software does not check whether an object is recursively defined, so a specially crafted message can drive the decoder into repeated processing until the stack overflows and the device crashes. The issue is rated HIGH and is addressed by [truncated]
A denial-of-service vulnerability exists in Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The product bundles SQLite 3.30.1, which contains a flaw in the sqlite3Select function (select.c) that triggers a crash when a subselect combines DISTINCT with window functions and specific ORDER BY clauses. Successful exploitation causes the application to crash, requiring a manual restart [truncated]