Vulnerabilities (CVE)

Filtered by vendor Rockwellautomation
Filtered by product Panelview Plus
Angry Yack Logo
Total 1 CVE
CVE Vendors Products Updated CVSS v2 CVSS v3
CVE-2023-2071 1 Rockwellautomation 2 Factorytalk View, Panelview Plus 2024-11-21 N/A 9.8 CRITICAL
Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device w ...

Show More