CVE-2024-37365: FactoryTalk View ME Remote Code Execution Vulnerability via Project Save Path
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by changing the macro to execute arbitrary code.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37365?
CVE-2024-37365 is classified as a remote code execution vulnerability.
How do I fix CVE-2024-37365?
To fix CVE-2024-37365, users should apply the latest security patches provided by Rockwell Automation.
What are the potential risks associated with CVE-2024-37365?
The potential risks include unauthorized modification or deletion of files by users with local access.
Which software is affected by CVE-2024-37365?
CVE-2024-37365 affects Rockwell Automation FactoryTalk View ME software.
Can CVE-2024-37365 be exploited remotely?
Yes, CVE-2024-37365 can be exploited remotely due to its nature as a remote code execution vulnerability.