Rockwell Automation FactoryTalk® Remote Access™ has Unquoted Executables
Vulnerability Description
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2024-3640
Credits & Attribution
No credits recorded in the NVD database.
More from Rockwell Automation
View All →Affected Vendor
Rockwell Automation
View all reports →