By using this site, you agree to the Privacy Policy and Terms of Use.
Accept
Viral Trending contentViral Trending content
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
Reading: Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus
Notification Show More
Viral Trending contentViral Trending content
  • Home
  • Categories
    • World News
    • Politics
    • Sports
    • Celebrity
    • Business
    • Crypto
    • Tech News
    • Gaming News
    • Travel
  • Bookmarks
© 2024 All Rights reserved | Powered by Viraltrendingcontent
Viral Trending content > Blog > Tech News > Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus
Tech News

Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus

By Viral Trending Content 3 Min Read
Share
SHARE

Jul 04, 2024NewsroomVulnerability / Critical Infrastructure

Rockwell Automation PanelView Plus

Microsoft has revealed two security flaws in Rockwell Automation PanelView Plus that could be weaponized by remote, unauthenticated attackers to execute arbitrary code and trigger a denial-of-service (DoS) condition.

“The [remote code execution] vulnerability in PanelView Plus involves two custom classes that can be abused to upload and load a malicious DLL into the device,” security researcher Yuval Gordon said.

“The DoS vulnerability takes advantage of the same custom class to send a crafted buffer that the device is unable to handle properly, thus leading to a DoS.”

Cybersecurity

The list of shortcomings is as follows –

  • CVE-2023-2071 (CVSS score: 9.8) – An improper input validation vulnerability that allows unauthenticated attackers to achieve remote code executed via crafted malicious packets.
  • CVE-2023-29464 (CVSS score: 8.2) – An improper input validation vulnerability that allows an unauthenticated threat actor to read data from memory via crafted malicious packets and result in a DoS by sending a packet larger than the buffer size

Successful exploitation of the twin flaws permits an adversary to execute code remotely or lead to information disclosure or a DoS condition.

Rockwell Automation PanelView Plus

While CVE-2023-2071 impacts FactoryTalk View Machine Edition (versions 13.0, 12.0, and prior), CVE-2023-29464 affects FactoryTalk Linx (versions 6.30, 6.20, and prior).

It’s worth noting that advisories for the flaws were released by Rockwell Automation on September 12, 2023, and October 12, 2023, respectively. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released its own alerts on September 21 and October 17.

Cybersecurity

The disclosure comes as unknown threat actors are believed to be exploiting a recently disclosed critical security flaw in HTTP File Server (CVE-2024-23692, CVSS score: 9.8) to deliver cryptocurrency miners and trojans such as Xeno RAT, Gh0st RAT, and PlugX.

The vulnerability, described as a case of template injection, allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request.

Found this article interesting? Follow us on Twitter  and LinkedIn to read more exclusive content we post.

You Might Also Like

Trump Phone T1 Launches in US: Design, Features, Background

AGIBOT A2 Brings Embodied AI to the Met Gala Alongside Alexander Wang

CISA flags Windows Task Host vulnerability as exploited in attacks

Anthropic sets sights on small business after enterprise push

Sony Xperia 1 VIII AI Camera Assistant Internet Outrage

TAGGED: critical infrastructure, Cyber Security, Cybersecurity, Denial of Service, industrial control system, Internet, Patch Management, Remote Code Execution, Threat Intelligence, Vulnerability
Share This Article
Facebook Twitter Copy Link
Previous Article Mercialys Has Been Awarded the 1st Prize for the ESG Transparency at the Transparency Awards
Next Article Google Introduces Gemma 2: Elevating AI Performance, Speed and Accessibility for Developers
Leave a comment

Leave a Reply Cancel reply

Your email address will not be published. Required fields are marked *

- Advertisement -
Ad image

Latest News

Women’s rights and demographics take centre stage at regional forum in Bukhara
World News
$10M Gone: Thorchain Exploit Triggers Security Fears Across DeFi
Crypto
Scientists spot ‘yellow brick road’ deep under the ocean and the explanation is even more surprising
World News
Trump Phone T1 Launches in US: Design, Features, Background
Tech News
Oil tanker arrives in South Korea after leaving the Strait of Hormuz
Business
US, Iran no closer to ending war as Qatari tanker sails toward Strait of Hormuz
Business
US CLARITY Act will be a ‘boon for domestic innovation’: A16z
Crypto

About Us

Welcome to Viraltrendingcontent, your go-to source for the latest updates on world news, politics, sports, celebrity, tech, travel, gaming, crypto news, and business news. We are dedicated to providing you with accurate, timely, and engaging content from around the globe.

Quick Links

  • Home
  • World News
  • Politics
  • Celebrity
  • Business
  • Home
  • World News
  • Politics
  • Sports
  • Celebrity
  • Business
  • Crypto
  • Gaming News
  • Tech News
  • Travel
  • Sports
  • Crypto
  • Tech News
  • Gaming News
  • Travel

Trending News

cageside seats

Unlocking the Ultimate WWE Experience: Cageside Seats News 2024

Women’s rights and demographics take centre stage at regional forum in Bukhara

Investing £5 a day could help me build a second income of £329 a month!

cageside seats
Unlocking the Ultimate WWE Experience: Cageside Seats News 2024
May 22, 2024
Women’s rights and demographics take centre stage at regional forum in Bukhara
May 17, 2026
Investing £5 a day could help me build a second income of £329 a month!
March 27, 2024
Brussels unveils plans for a European Degree but struggles to explain why
March 27, 2024
© 2024 All Rights reserved | Powered by Vraltrendingcontent
  • About Us
  • Contact US
  • Disclaimer
  • Privacy Policy
  • Terms of Service
Welcome Back!

Sign in to your account

Lost your password?