Show filters
23 Total Results
Displaying 1-10 of 23
Sort by:
Attacker Value
Unknown

CVE-2025-24482

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
0
Attacker Value
Unknown

CVE-2025-24481

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.
0
Attacker Value
Unknown

CVE-2025-24480

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.
0
Attacker Value
Unknown

CVE-2025-24479

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
0
Attacker Value
Unknown

CVE-2024-37365

Disclosure Date: November 12, 2024 (last updated November 13, 2024)
A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this vulnerability to escalate their privileges by changing the macro to execute arbitrary code.
0
Attacker Value
Unknown

CVE-2024-45823

Disclosure Date: September 12, 2024 (last updated October 03, 2024)
CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.
Attacker Value
Unknown

CVE-2024-45824

Disclosure Date: September 12, 2024 (last updated February 01, 2025)
CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.
Attacker Value
Unknown

CVE-2024-7513

Disclosure Date: August 14, 2024 (last updated February 01, 2025)
CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.
Attacker Value
Unknown

CVE-2024-37369

Disclosure Date: June 14, 2024 (last updated February 01, 2025)
A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system.
Attacker Value
Unknown

CVE-2024-37368

Disclosure Date: June 14, 2024 (last updated February 01, 2025)
A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication verification.