CVE-2024-4609 HIGH

CVE-2024-4609: Rockwell Automation Datalog Function within in FactoryTalk® View SE contains SQL Injection Vulnerability

Vendor Rockwell Automation
Product FactoryTalk® View SE
Weakness CWE-20 · Input validation
Published May 16, 2024
Last update August 1, 2024

CVSS base score

8.8/10
Attack vector Network
Attack complexity Low
Privileges required None
User interaction None
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure, revealing sensitive information. Additionally, a threat actor could potentially modify and delete the data in a remote database. An attack would only affect the HMI design time, not runtime.

Key dates

02Disclosure timeline

May 16, 2024 CVE published
August 1, 2024 Record updated