This content is restricted.
Brief
Here is a summary of the document in a concise and standardized format:
Summary:
A critical vulnerability has been identified in Rockwell Automation's FactoryTalk Activation Manager and Studio 5000 Logix Designer, with a CVSS v3 score of 9.8. The vulnerability is exploitable remotely with low attack complexity, allowing an attacker to gain full access to the system. Specifically, the affected products use Wibu-Systems' CodeMeter which contains a buffer overflow vulnerability (CVE-2023-38545) that can be exploited to achieve RCE. The CVE-2023-3935 vulnerability affects the same products and is a heap buffer overflow that allows an unauthenticated, remote attacker to achieve RCE. A patch upgrade to FactoryTalk Activation Manager 5.01 is recommended. Users are encouraged to minimize network exposure, implement firewalls, and use secure remote access methods. Additional mitigation guidance and recommended practices are publicly available on the CISA website.
Metrics:
CVSS v3 score: 9.8
Severity: High
Attack complexity: Low
Remote access: Yes
Highlights content goes here...
This content is restricted.
