Rockwell Automation FactoryTalk View SE
75Vexday Risk Score
Corrija em breve. Ela tem exploit funcional público.
ssvc Attendcvss 9epss 47%
da publicação à arma0 dias
Publicada no NVD20 de jul.
metasploit22 de jun.
probabilidade de exploração
47%top 1% das CVEs
exploração observada
nãonenhuma fonte reporta
1 exploit(s) público(s)
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before installing this patch, the patch rollup dated 06 Apr 2020 or later MUST be applied. 1066644 – Patch Roll-up for CPR9 SRx.
CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:N
Produtos afetados
Rockwell Automation · FactoryTalk View SEPoCs públicas encontradas — 1
cve_referencepacketstormsecurity.com/files/160156/Rockwell-FactoryTalk-View-SE-SCADA-Unauthenticated-Remote-Code-Execution.htmlnão verificado⚠ Recursos públicos, para você avaliar a exposição de sistemas que controla ou está autorizado a testar. Teste apenas com autorização.