CVE-2024-3640

An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
CVSS

No CVSS.

Configurations

No configuration.

History

21 Nov 2024, 09:30

Type Values Removed Values Added
References () https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD1671.html -

17 May 2024, 18:36

Type Values Removed Values Added
New CVE

Information

Published : 2024-05-16 16:15

Updated : 2024-11-21 09:30


NVD link : CVE-2024-3640

Mitre link : CVE-2024-3640

CVE.ORG link : CVE-2024-3640


JSON object : View

Products Affected

No product.

CWE
CWE-428

Unquoted Search Path or Element