HomeSecurityMicrosoft: Discloses Critical Vulnerabilities in Rockwell Automation PanelView Plus

Microsoft: Discloses Critical Vulnerabilities in Rockwell Automation PanelView Plus

Microsoft has disclosed two critical vulnerabilities in Rockwell Automation PanelView Plus, which could be exploited by remote, unauthorized users to execute arbitrary code and trigger a denial of service (DoS) attack .

microsoft rockwell vulnerabilities

«The remote code execution vulnerability in PanelView Plus includes two custom categories that can be exploited to upload a malicious DLL to the device», explained security researcher Yuval Gordon.

See more: Rockwell Automation tells administrators to disconnect ICS devices

«The DoS vulnerability exploits a specially crafted category to send a modified buffer, which the device fails to handle correctly, thus leading to DoS.»»

The list of vulnerabilities is as follows –

  • CVE-2023-2071 (CVSS score: 9.8) – A vulnerability in data verification allows unauthorized users to execute remote code via malicious packets.
  • CVE-2023-29464 (CVSS score: 8.2) – A flaw in input validation allows an unauthorized user to read memory data via malicious packets and cause a denial‑of‑service (DoS) attack by sending a packet larger than the buffer size.

Read also: Attacks against Ukraine via old Microsoft Office vulnerability

Successful exploitation of these two vulnerabilities could allow an attacker to remotely execute code, disclose information, or cause a DoS condition. CVE-2023-2071 affects FactoryTalk View Machine Edition (versions 13.0, 12.0, and earlier), while CVE-2023-29464 affects FactoryTalk Linx (versions 6.30, 6.20, and earlier).

It is worth noting that Rockwell Automation issued advisories for the vulnerabilities on September 12 and October 12, 2023, respectively. The U.S. Cybersecurity and Infrastructure Security Administration (CISA) published its own alerts on September 21 and October 17.

microsoft rockwell vulnerabilities

Unknown threat actors are reportedly exploiting a recently discovered critical security flaw in the HTTP file server (CVE-2024-23692, CVSS score: 9.8) to distribute cryptocurrency and trojans such as Xeno RAT, Gh0st RAT, and PlugX.

See also: Microsoft: Informs customers that Russian hackers were spying on emails

The vulnerabilities allow a remote, unauthenticated hacker to execute commands on the system by sending a specially crafted HTTP request.

Source: thehackernews

Selecting the team

🔒 Protect your privacy with Proton VPN

Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.

  • ✔ No-logs, based in Switzerland (except 14-Eyes)
  • ✔ NetShield: blocks ads, trackers & malicious domains
  • ✔ Covers all devices — free version available
Try Proton VPN for free — 30-day money-back guarantee →

The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.

📧
Subscribe to the SecNews Newsletter

The most important Security & Technology news in your Inbox.

SecNews
SecNewshttps://www.secnews.gr
In a world without fences and walls, who needs Gates and Windows

SEARCH

FOLLOW US

📧
Newsletter SecNews
The most important Security & Technology news in your inbox.

LIVE NEWS