Article Details
Scrape Timestamp (UTC): 2024-07-04 09:15:58.792
Source: https://thehackernews.com/2024/07/microsoft-uncovers-critical-flaws-in.html
Original Article Text
Click to Toggle View
Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus. Microsoft has revealed two security flaws in Rockwell Automation PanelView Plus that could be weaponized by remote, unauthenticated attackers to execute arbitrary code and trigger a denial-of-service (DoS) condition. "The [remote code execution] vulnerability in PanelView Plus involves two custom classes that can be abused to upload and load a malicious DLL into the device," security researcher Yuval Gordon said. "The DoS vulnerability takes advantage of the same custom class to send a crafted buffer that the device is unable to handle properly, thus leading to a DoS." The list of shortcomings is as follows - Successful exploitation of the twin flaws permits an adversary to execute code remotely or lead to information disclosure or a DoS condition. While CVE-2023-2071 impacts FactoryTalk View Machine Edition (versions 13.0, 12.0, and prior), CVE-2023-29464 affects FactoryTalk Linx (versions 6.30, 6.20, and prior). It's worth noting that advisories for the flaws were released by Rockwell Automation on September 12, 2023, and October 12, 2023, respectively. The U.S. Cybersecurity and Infrastructure Security Agency (CISA) released its own alerts on September 21 and October 17. The disclosure comes as unknown threat actors are believed to be exploiting a recently disclosed critical security flaw in HTTP File Server (CVE-2024-23692, CVSS score: 9.8) to deliver cryptocurrency miners and trojans such as Xeno RAT, Gh0st RAT, and PlugX. The vulnerability, described as a case of template injection, allows a remote, unauthenticated attacker to execute arbitrary commands on the affected system by sending a specially crafted HTTP request. Continuous Attack Surface Discovery & Penetration Testing Continuously discover, prioritize, & mitigate exposures with evidence-backed ASM, Pentesting, and Red Teaming.
Daily Brief Summary
Microsoft has discovered two significant security vulnerabilities in Rockwell Automation PanelView Plus that could allow hackers remote access without authentication.
These vulnerabilities can enable attackers to execute arbitrary code or cause a denial-of-service (DoS) condition by abusing specific custom classes in the system.
The first vulnerability, labeled CVE-2023-2071, affects FactoryTalk View Machine Edition and allows remote code execution and data leakage.
The second, CVE-2023-29464, impacts FactoryTalk Linx and primarily facilitates conditions for a denial-of-service attack.
Rockwell Automation issued advisories on these vulnerabilities on September 12 and October 12, 2023, while CISA followed with alerts shortly after each advisory.
These disclosures coincide with reports of active exploitation of other critical vulnerabilities, such as CVE-2024-23692 in HTTP File Server, by attackers deploying cryptocurrency miners and trojans.
These events underscore the importance of continuous vigilance and updating security protocols to protect against evolving cyber threats.