CVE-2024-45824

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations section below contains patches to fix this issue.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:*

History

31 Jan 2025, 15:25

Type Values Removed Values Added
First Time Rockwellautomation
Rockwellautomation factorytalk View
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1696.html - Vendor Advisory
CPE cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:se:*:*:*
Summary
  • (es) CVE-2024-45824 IMPACTO Existe una vulnerabilidad de código remoto en los productos afectados. La vulnerabilidad se produce cuando se combina con vulnerabilidades de path traversal, inyección de comandos y XSS y permite la ejecución de código remoto sin autenticación. El enlace en la sección de mitigaciones a continuación contiene parches para solucionar este problema.

12 Sep 2024, 14:16

Type Values Removed Values Added
New CVE

Information

Published : 2024-09-12 14:16

Updated : 2025-01-31 15:25


NVD link : CVE-2024-45824

Mitre link : CVE-2024-45824

CVE.ORG link : CVE-2024-45824


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_view
CWE
CWE-77

Improper Neutralization of Special Elements used in a Command ('Command Injection')