First published: Sat Dec 23 2017(Updated: )
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver service), causing the service to either stall or terminate.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Factorytalk Alarms And Events | <=2.90 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2017-14022.
The severity level of CVE-2017-14022 is high with a severity value of 7.5.
The affected software for CVE-2017-14022 is Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier.
An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can exploit CVE-2017-14022 by sending a specially crafted set of packets to Port 403/TCP.
Please refer to the references provided for information on any available fixes or patches for CVE-2017-14022.