CVE-2024-37367: Rockwell Automation FactoryTalk® View SE v12 Information Leakage Vulnerability via Authentication Restriction
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-37367?
CVE-2024-37367 is classified as a user authentication vulnerability that can potentially allow unauthorized access to HMI projects.
How do I fix CVE-2024-37367?
To fix CVE-2024-37367, update Rockwell Automation FactoryTalk View SE to a version after v14.0.
What specific software versions are affected by CVE-2024-37367?
CVE-2024-37367 affects Rockwell Automation FactoryTalk View SE versions from 12.0 to 14.0.
Can CVE-2024-37367 be exploited remotely?
Yes, CVE-2024-37367 can be exploited remotely by a user with FTView capabilities.
What does CVE-2024-37367 allow an attacker to do?
CVE-2024-37367 allows an attacker to view HMI projects without proper authentication.