First published: Tue Nov 12 2024(Updated: )
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by changing the macro to execute arbitrary code.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk View ME | ||
FactoryTalk View | =14.0 |
Upgrade to Version 15
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-37365 is classified as a remote code execution vulnerability.
To fix CVE-2024-37365, users should apply the latest security patches provided by Rockwell Automation.
The potential risks include unauthorized modification or deletion of files by users with local access.
CVE-2024-37365 affects Rockwell Automation FactoryTalk View ME software.
Yes, CVE-2024-37365 can be exploited remotely due to its nature as a remote code execution vulnerability.