First published: Thu Oct 27 2022(Updated: )
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Factorytalk Alarms And Events |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-38744 is a vulnerability that allows an unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service to cause the service to fault and become unavailable.
CVE-2022-38744 has a severity level of 7.5 (High).
CVE-2022-38744 affects Rockwell Automation FactoryTalk Alarm and Events service by allowing an unauthenticated attacker to open a connection, causing the service to fault and become unavailable.
To fix CVE-2022-38744, it is recommended to apply the necessary patches or updates provided by Rockwell Automation, and ensure that the affected port is not accessible from untrusted networks.
You can find more information about CVE-2022-38744 on the Rockwell Automation website at the following link: https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1136876