CVE-2025-24482: FactoryTalk® View Site Edition - Local Code Injection
Published Jan 28, 2025
·Updated
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
Affected Software
1 affected component
Rockwell Automation FactoryTalk View Site Edition
Remediation
Information
Upgrade to V15 or apply patch. Answer ID 1152304
Event History
Jan 28, 2025
CVE Published
via MITRE·08:59 PM
Data Sourced
via MITRE·08:59 PM
RemedyDescriptionWeakness
Data Sourced
via NVD·09:15 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the severity of CVE-2025-24482?
CVE-2025-24482 is considered a critical severity vulnerability due to its potential for local code execution.
2
How do I fix CVE-2025-24482?
To fix CVE-2025-24482, ensure that proper permissions are set to prevent the execution of DLLs with elevated permissions.
3
What software is affected by CVE-2025-24482?
CVE-2025-24482 specifically affects Rockwell Automation FactoryTalk View Site Edition.
4
When was CVE-2025-24482 disclosed?
CVE-2025-24482 was disclosed as part of ongoing security monitoring.
5
What are the implications of CVE-2025-24482?
The implications of CVE-2025-24482 include unauthorized execution of code, which could compromise system integrity and security.