Loading HuntDB...

GHSA-5cg3-92mh-qgvc

GitHub Security Advisory

⚠ Unreviewed CRITICAL Has CVE

Advisory Details


Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

Related CVEs

Key Information

GHSA ID
GHSA-5cg3-92mh-qgvc
Published
September 12, 2023 3:30 PM
Last Modified
April 4, 2024 7:37 AM
CVSS Score
9.0 /10
Primary Ecosystem
Unknown
Primary Package
Unknown
GitHub Reviewed
✗ No

Dataset

Last updated: July 4, 2025 6:27 AM

Data from GitHub Advisory Database. This information is provided for research and educational purposes.