← Back to home
ICSA-23-164-04  ·  Published 2023-06-13  ·  View on CISA ICS-CERT ↗

Rockwell Automation FactoryTalk Transaction Manager

CVSS 7.5 HIGH

Risk Summary

Successful exploitation of this vulnerability could cause the application to crash or experience a high CPU or memory usage condition, causing intermittent application functionality issues. The user would need to restart the application to recover from the denial of service.

CVEs (1)

Remediations

  • Rockwell Automation encourages affected software users to install one of the following security patches to address the associated risk:
  • FactoryTalk Transaction Manager: v13.00 Security Patch
  • FactoryTalk Transaction Manager: v13.10 Security Patch
  • Users who are unable to update are directed towards the risk mitigation strategies provided below and are encouraged, when possible, to implement Rockwell Automation's suggested security best practices to minimize the risk.
  • Users should follow the instructions in the Knowledgebase article BF29042 to install the patch to mitigate the issue.
  • Security Best Practices.
  • Please see the Rockwell Automation publication regarding this issue for more information.

Affected Vendors

Rockwell Automation

Affected Products (1)

Rockwell Automation · FactoryTalk Transaction Manager <= 13.10

Affected Sectors

Food and Agriculture, Transportation Systems, Water and Wastewater Systems

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more