First published: Tue Jan 28 2025(Updated: )
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk View ME |
Upgrade to V15.00 or apply patch in AID 1152309
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-24479 has a high severity rating due to its potential for local code execution.
To mitigate CVE-2025-24479, update your Rockwell Automation FactoryTalk View Machine Edition to the latest version that addresses the vulnerability.
CVE-2025-24479 primarily affects Rockwell Automation FactoryTalk View Machine Edition.
The risks associated with CVE-2025-24479 include unauthorized access to the Command Prompt with elevated privileges, leading to potential system compromise.
If immediate patching for CVE-2025-24479 is not possible, consider restricting access to affected systems and monitoring for unusual activity.