CVE-2024-3640

CVSS V2 None CVSS V3 None
Description
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
Overview
  • CVE ID
  • CVE-2024-3640
  • Assigner
  • Rockwell
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2024-05-16T15:25:28.558Z
  • Last Modified Date
  • 2024-06-04T17:31:28.680Z
History
Created Old Value New Value Data Type Notes
2024-06-23 23:02:23 Added to TrackCVE