CVE-2024-3640

An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 09:30

Type Values Removed Values Added
Summary
  • (es) Existe una ruta ejecutable sin comillas en Rockwell Automation FactoryTalk® Remote Access™ que, si se explota, podría provocar la ejecución remota de código. Mientras se ejecuta el paquete de instalación de FTRA, la ruta del ejecutable no se cita correctamente, lo que podría permitir que un actor de amenazas ingrese un ejecutable malicioso y lo ejecute como usuario del sistema. Un actor malicioso necesita privilegios de administrador para explotar esta vulnerabilidad.
References () https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html -

16 May 2024, 16:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-16 16:15

Updated : 2024-11-21 09:30


NVD link : CVE-2024-3640

Mitre link : CVE-2024-3640

CVE.ORG link : CVE-2024-3640


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element