Microsoft has disclosed two critical vulnerabilities in Rockwell Automation PanelView Plus, which could be exploited by remote, unauthorized users to execute arbitrary code and trigger a denial of service (DoS) attack .

«The remote code execution vulnerability in PanelView Plus includes two custom categories that can be exploited to upload a malicious DLL to the device», explained security researcher Yuval Gordon.
See more: Rockwell Automation tells administrators to disconnect ICS devices
«The DoS vulnerability exploits a specially crafted category to send a modified buffer, which the device fails to handle correctly, thus leading to DoS.»»
The list of vulnerabilities is as follows –
- CVE-2023-2071 (CVSS score: 9.8) – A vulnerability in data verification allows unauthorized users to execute remote code via malicious packets.
- CVE-2023-29464 (CVSS score: 8.2) – A flaw in input validation allows an unauthorized user to read memory data via malicious packets and cause a denial‑of‑service (DoS) attack by sending a packet larger than the buffer size.
Read also: Attacks against Ukraine via old Microsoft Office vulnerability
Successful exploitation of these two vulnerabilities could allow an attacker to remotely execute code, disclose information, or cause a DoS condition. CVE-2023-2071 affects FactoryTalk View Machine Edition (versions 13.0, 12.0, and earlier), while CVE-2023-29464 affects FactoryTalk Linx (versions 6.30, 6.20, and earlier).
It is worth noting that Rockwell Automation issued advisories for the vulnerabilities on September 12 and October 12, 2023, respectively. The U.S. Cybersecurity and Infrastructure Security Administration (CISA) published its own alerts on September 21 and October 17.

Unknown threat actors are reportedly exploiting a recently discovered critical security flaw in the HTTP file server (CVE-2024-23692, CVSS score: 9.8) to distribute cryptocurrency and trojans such as Xeno RAT, Gh0st RAT, and PlugX.
See also: Microsoft: Informs customers that Russian hackers were spying on emails
The vulnerabilities allow a remote, unauthenticated hacker to execute commands on the system by sending a specially crafted HTTP request.
Source: thehackernews
🔒 Protect your privacy with Proton VPN
Swiss VPN from the creators of Proton Mail — strict no-logs policy, strong encryption, and built-in NetShield that blocks ads, trackers, & malware.
- ✔ No-logs, based in Switzerland (except 14-Eyes)
- ✔ NetShield: blocks ads, trackers & malicious domains
- ✔ Covers all devices — free version available
The link is an affiliate link — SecNews may receive a commission at no additional cost to you. It does not affect the independence of our article writing.
