Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2024-3640

Опубликовано: 16 мая 2024
Источник: nvd
EPSS Низкий

Описание

An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.

EPSS

Процентиль: 62%
0.00434
Низкий

Дефекты

CWE-428

Связанные уязвимости

github
больше 1 года назад

An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.

CVSS3: 6.5
fstec
больше 1 года назад

Уязвимость установочного пакета FTRA программного средства обеспечения удаленного доступа к системам автоматизации производства Rockwell Automation FactoryTalk Remote Access, позволяющая нарушителю выполнить произвольный код

EPSS

Процентиль: 62%
0.00434
Низкий

Дефекты

CWE-428