CVE-2024-45824 IMPACT
A remote
code vulnerability exists in the affected products. The vulnerability occurs
when chained with Path Traversal, Command Injection, and XSS Vulnerabilities
and allows for full unauthenticated remote code execution. The link in the
mitigations section below contains patches to fix this issue.
References
Link | Resource |
---|---|
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html | Vendor Advisory |
Configurations
History
31 Jan 2025, 15:25
Type | Values Removed | Values Added |
---|---|---|
Summary |
|
|
CPE | cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:* | |
References | () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html - Vendor Advisory | |
First Time |
Rockwellautomation factorytalk View
Rockwellautomation |
12 Sep 2024, 14:16
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-09-12 14:16
Updated : 2025-01-31 15:25
NVD link : CVE-2024-45824
Mitre link : CVE-2024-45824
CVE.ORG link : CVE-2024-45824
JSON object : View
Products Affected
rockwellautomation
- factorytalk_view
CWE
CWE-77
Improper Neutralization of Special Elements used in a Command ('Command Injection')