← Back to home
ICSA-21-308-02  ·  Published 2021-11-04  ·  View on CISA ICS-CERT ↗

AzeoTech DAQFactory

CVSS 7.8 HIGH

Risk Summary

Successful exploitation of these vulnerabilities could allow code execution, memory corruption, or unauthorized access to user information.

Remediations

  • Users are discouraged from using documents from unknown/untrusted sources.
  • Users are encouraged to store .ctl files in a folder only writeable by admin-level users.
  • Users are encouraged to operate in “Safe Mode” when loading documents that have been out of their control.
  • Users are encouraged to apply a document editing password to their documents.
  • Users should avoid using the Real Time Web-Connect menu items and instead connect to DAQConnect using script.

Affected Vendors

AzeoTech

Affected Products (1)

AzeoTech · DAQFactory < 18.1 Build 2347

Affected Sectors

Critical Manufacturing, Energy, Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more