CVE-2024-45824: FactoryTalk® View Site Edition Remote Code Execution Vulnerability via Lack of Input Validation
CVE-2024-45824 IMPACT
A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-45824?
CVE-2024-45824 is classified as a critical severity vulnerability allowing unauthenticated remote code execution.
How do I fix CVE-2024-45824?
To mitigate CVE-2024-45824, it is recommended to apply the latest security patches provided by Rockwell Automation.
What products are affected by CVE-2024-45824?
CVE-2024-45824 affects Rockwell Automation's FactoryTalk View Site Edition versions 12.0 to 14.0.
Can CVE-2024-45824 be exploited remotely?
Yes, CVE-2024-45824 allows for full unauthenticated remote code execution when exploited.
What types of vulnerabilities are chainable with CVE-2024-45824?
CVE-2024-45824 can be chained with Path Traversal, Command Injection, and XSS vulnerabilities.