First published: Mon Oct 17 2022(Updated: )
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Factorytalk Vantagepoint | =8.0 | |
Rockwellautomation Factorytalk Vantagepoint | =8.10 | |
Rockwellautomation Factorytalk Vantagepoint | =8.20 | |
Rockwellautomation Factorytalk Vantagepoint | =8.30 | |
Rockwellautomation Factorytalk Vantagepoint | =8.31 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-3158 is a vulnerability in Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, and 8.31.
CVE-2022-3158 has a severity rating of 8.8 (high).
CVE-2022-3158 affects Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, and 8.31 by allowing unauthorized retrieval of information from the back-end database through SQL statements.
To fix CVE-2022-3158, it is recommended to update to a patched version provided by Rockwell Automation.
More information about CVE-2022-3158 can be found at the following link: [CVE-2022-3158](https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1137043).