CVE-2024-37368

HIGH

Rockwell Automation FactoryTalk View SE 11.0-13.0 - Unauthenticated HMI Project Access

Title source: llm
STIX 2.1

Description

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication verification.

Scores

CVSS v3 7.5
EPSS 0.0014
EPSS Percentile 33.3%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-287 CWE-306
Status published
Products (1)
rockwellautomation/factorytalk_view 11.0 - 14.0
Published Jun 14, 2024
Tracked Since Feb 18, 2026