← Back to home
ICSA-23-264-06  ·  Published 2023-09-21  ·  View on CISA ICS-CERT ↗

Rockwell Automation FactoryTalk View Machine Edition

CVSS 9.8 CRITICAL

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to execute code remotely with specially crafted malicious packets or by using a self-made library to bypass security checks.

CVEs (1)

Remediations

  • Rockwell recommends updating FactoryTalk View Machine Edition with v12.0 & v13.0 patch
  • Users of the affected versions are encouraged by Rockwell Automation to upgrade to corrected firmware revisions. Uers are also strongly encouraged to implement Rockwell Automation's suggested security best practices to minimize the risk of the vulnerability.
  • Install the security patches for the respective versions
  • Security Best Practices
  • For more information and to see Rockwell's detection rules, see Rockwell Automation's Security Advisory.

Affected Vendors

Rockwell Automation

Affected Products (2)

Rockwell Automation · FactoryTalk View Machine Edition v13.0
Rockwell Automation · FactoryTalk View Machine Edition <= 12.0

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more