Brief

Here is a summary of the document in a concise and standardized format:

Summary:

A critical vulnerability has been identified in Rockwell Automation's FactoryTalk Activation Manager and Studio 5000 Logix Designer, with a CVSS v3 score of 9.8. The vulnerability is exploitable remotely with low attack complexity, allowing an attacker to gain full access to the system. Specifically, the affected products use Wibu-Systems' CodeMeter which contains a buffer overflow vulnerability (CVE-2023-38545) that can be exploited to achieve RCE. The CVE-2023-3935 vulnerability affects the same products and is a heap buffer overflow that allows an unauthenticated, remote attacker to achieve RCE. A patch upgrade to FactoryTalk Activation Manager 5.01 is recommended. Users are encouraged to minimize network exposure, implement firewalls, and use secure remote access methods. Additional mitigation guidance and recommended practices are publicly available on the CISA website.

Metrics:

CVSS v3 score: 9.8
Severity: High
Attack complexity: Low
Remote access: Yes

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: FactoryTalk Activation Manager Vulnerabilities: Out-of-Bounds Write 2. RISK EVALUATION Successful exploitation of these vulnerabilities could result in a buffer overflow and allow the attacker to gain full access to the system. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The

This content is restricted.

Highlights content goes here...

View CSAF 1. EXECUTIVE SUMMARY CVSS v3 9.8 ATTENTION: Exploitable remotely/low attack complexity Vendor: Rockwell Automation Equipment: FactoryTalk Activation Manager Vulnerabilities: Out-of-Bounds Write 2. RISK EVALUATION Successful exploitation of these vulnerabilities could result in a buffer overflow and allow the attacker to gain full access to the system. 3. TECHNICAL DETAILS 3.1 AFFECTED PRODUCTS The

This content is restricted.

Cybersecurity and Infrastructure Security Agency

Quick Insight
RADA.AI
RADA.AI
Hello! I'm RADA.AI - Regulatory Analysis and Decision Assistance. Your Intelligent guide for compliance and decision-making. How can i assist you today?
Suggested

Form successfully submitted. One of our GRI rep will contact you shortly

Thanking You!

Enter your Email

Enter your registered username/email id.

Enter your Email

Enter your email id below to signup.
Individual Plan
$125 / month OR $1250 / year
Features
Best for: Researchers, Legal professionals, Academics
Enterprise Plan
Contact for Pricing
Features
Best for: Law Firms, Corporations, Government Bodies