FactoryTalk Fiasco: Critical Security Flaw Puts Industrial Control Systems at Risk

Attention FactoryTalk users: A CVSS v4.0 score of 8.5 vulnerability allows unauthorized file edits, triggering code execution with elevated permissions. Rockwell Automation urges immediate security updates and best practices to mitigate risks.

Hot Take:

“Rockwell Automation: Where even your grandma can become a hacker with just a pinch of permissions mismanagement!”

Key Points:

  • Critical vulnerability (CVSS v4 8.5) in Rockwell Automation’s FactoryTalk View Site Edition.
  • Easy-to-exploit flaw due to incorrect permission assignments.
  • Allows any user to edit or replace files executed with elevated permissions.
  • Affects FactoryTalk version 13.0 and FactoryTalk View SE version 13.0.
  • Mitigation steps include tightening folder permissions and following security best practices.

Membership Required

 You must be a member to access this content.

View Membership Levels
Already a member? Log in here