CVE-2023-46289 Vulnerability Details

  /     /     /  

CVE-2023-46289 Metadata Quick Info

CVE Published: 27/10/2023 | CVE Updated: 02/08/2024 | CVE Year: 2023
Source: Rockwell | Vendor: Rockwell Automation | Product: FactoryTalk® View Site Edition
Status : PUBLISHED

CVE-2023-46289 Description

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition.

Metrics

CVSS Version: 3.1 | Base Score: 7.5 HIGH
Vector: CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

l➤ Exploitability Metrics:
    Attack Vector (AV)* NETWORK
    Attack Complexity (AC)* LOW
    Privileges Required (PR)* NONE
    User Interaction (UI)* NONE
    Scope (S)* UNCHANGED

l➤ Impact Metrics:
    Confidentiality Impact (C)* NONE
    Integrity Impact (I)* NONE
    Availability Impact (A)* HIGH

Weakness Enumeration (CWE)

CWE-ID: CWE-20
CWE Name: CWE-20 Improper Input Validation
Source: Rockwell Automation

Common Attack Pattern Enumeration and Classification (CAPEC)

CAPEC-ID: CAPEC-629
CAPEC Description: CAPEC-629 Unauthorized Use of Device Resources


Source: NVD (National Vulnerability Database).