First published: Mon Mar 25 2024(Updated: )
A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk View ME | ||
Rockwell Automation PanelView Plus 7 |
Users using the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible. * Security Best Practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-21914 is classified as a high-severity vulnerability due to its potential to allow unauthorized remote access.
To mitigate CVE-2024-21914, apply the latest firmware updates provided by Rockwell Automation for affected products.
CVE-2024-21914 affects the Rockwell Automation PanelView Plus 7 terminals and FactoryTalk View ME software.
Exploitation of CVE-2024-21914 can lead to unauthorized remote restarts of the terminal, resulting in loss of control or visibility.
While updates are the primary solution, limiting remote access and implementing network segmentation can serve as temporary workarounds.