{ "id": "CVE-2023-2071", "sourceIdentifier": "PSIRT@rockwellautomation.com", "published": "2023-09-12T14:15:09.663", "lastModified": "2024-11-21T07:57:52.790", "vulnStatus": "Modified", "cveTags": [], "descriptions": [ { "lang": "en", "value": "\nRockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user\u2019s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. \u00a0The device has the functionality, through a CIP class, to execute exported functions from libraries. \u00a0There is a routine that restricts it to execute specific functions from two dynamic link library files. \u00a0By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.\n\n" }, { "lang": "es", "value": "Rockwell Automation FactoryTalk View Machine Edition en PanelView Plus verifica incorrectamente la entrada del usuario, lo que permite a un atacante no autenticado lograr la ejecuci\u00f3n remota de c\u00f3digo a trav\u00e9s de paquetes maliciosos manipulados. El dispositivo tiene la funcionalidad, a trav\u00e9s de una clase CIP, de ejecutar funciones exportadas desde librer\u00eda. Existe una rutina que lo restringe a ejecutar funciones espec\u00edficas desde dos archivos de librer\u00eda de enlaces din\u00e1micos. Al utilizar una clase CIP, un atacante puede cargar una biblioteca de creaci\u00f3n propia en el dispositivo que le permite eludir el control de seguridad y ejecutar cualquier c\u00f3digo escrito en la funci\u00f3n." } ], "metrics": { "cvssMetricV31": [ { "source": "PSIRT@rockwellautomation.com", "type": "Secondary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 5.9 }, { "source": "nvd@nist.gov", "type": "Primary", "cvssData": { "version": "3.1", "vectorString": "CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H", "baseScore": 9.8, "baseSeverity": "CRITICAL", "attackVector": "NETWORK", "attackComplexity": "LOW", "privilegesRequired": "NONE", "userInteraction": "NONE", "scope": "UNCHANGED", "confidentialityImpact": "HIGH", "integrityImpact": "HIGH", "availabilityImpact": "HIGH" }, "exploitabilityScore": 3.9, "impactScore": 5.9 } ] }, "weaknesses": [ { "source": "PSIRT@rockwellautomation.com", "type": "Secondary", "description": [ { "lang": "en", "value": "CWE-20" } ] }, { "source": "nvd@nist.gov", "type": "Primary", "description": [ { "lang": "en", "value": "CWE-434" } ] } ], "configurations": [ { "operator": "AND", "nodes": [ { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": true, "criteria": "cpe:2.3:a:rockwellautomation:factorytalk_view:*:*:*:*:machine:*:*:*", "versionEndIncluding": "13.0", "matchCriteriaId": "D10953CE-C43E-4F1E-B9E7-48CDE0D7DA05" } ] }, { "operator": "OR", "negate": false, "cpeMatch": [ { "vulnerable": false, "criteria": "cpe:2.3:h:rockwellautomation:panelview_plus:-:*:*:*:*:*:*:*", "matchCriteriaId": "96B37F97-FE57-4437-8D5D-64561CAD1BE9" } ] } ] } ], "references": [ { "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140724", "source": "PSIRT@rockwellautomation.com", "tags": [ "Vendor Advisory" ] }, { "url": "https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1140724", "source": "af854a3a-2127-422b-91ae-364da2661108", "tags": [ "Vendor Advisory" ] } ] }