Rockwell FactoryTalk View Site Edition Vulnerability

Advisory Details

  • Issue Date:

    May 20, 2024

  • Importance

    High

  • Summary

    Rockwell FactoryTalk View Site Edition Vulnerability

  • Systems Impacted

    All OT/ICS Environments

On May 16th 2024, Rockwell Automation reported a new improper input validation vulnerability CVE-2024-4609 affecting their FactoryTalk View Site Edition HMI software which can be exploited remotely and with low attack complexity. The vulnerability exists in the software’s Datalog function potentially allowing adversaries to inject a malicious SQL statement if the SQL database has no authentication setup, or if legitimate access credentials have been stolen. If successfully exploited, it could result in the exposure of sensitive site information along with the attacker’s ability to modify and delete remote database information. This type of attack would only affect the HMI design time, not runtime.

📝 Affected Software Version(s)

FactoryTalk View Site Edition Versions prior to 14.0

Actions and/or Recommendations

  • Determine if CVE-2024-4609 impacts current FactoryTalk software in your OT environment.
  • Engage Mangan Cybersecurity for assistance and ensure projects moving forward are managing this CVE.
  • Upgrade FactoryTalk View Site Edition to software version 14.0
  • Reduce network visibility for all control system devices and systems ensuring they are not accessible from the internet.
  • Locate and isolate control system networks and remote devices behind firewalls from the enterprise network.
  • Develop a monitoring strategy to identify undesired access or activity on your control systems networks.
  • Always Re-enforce OT Cybersecurity Best Practices when no patches or software updates exist for a vulnerability.

Mangan Cybersecurity has well established templates and techniques to assist with the above suggestions expediently and effectively. Mangan is a customer of its own products/services recommended within published cybersecurity advisories.

About REAL Matters and Mangan Inc.

REAL Matters advisories are published to communicate cybersecurity threats and risks within the Operational Technology (OT) environment and where Critical Infrastructure vulnerabilities are identified. The purpose of this newsletter is to inform, propose suggested approaches to mitigate the risk as well as provide feedback on how Mangan Cybersecurity is approaching the issue(s) addressed.

Mangan Inc. is a nationally-recognized Specialty Engineering, Automation, and Integration company, providing a full-range of services to the Oil & Gas, Refining, Pipeline, Chemicals, and Life Sciences Industries. Established in Long Beach, California in 1990, Mangan’s multiple office locations include sites in California, Georgia, New Hampshire, North Carolina, Texas, and Louisiana. Mangan’s 350+ employee-owners bring expertise, innovation, and safety as their core mission to some of the largest companies in the world.

Scroll to Top