CVE-2014-9209
Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an…
Does this matter?
Lower severity and a low EPSS score (0.69%). Track it; it rarely justifies an emergency change on its own.
Description
Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain privileges via a Trojan horse DLL in an unspecified directory.
- CVSS 2.0
- 6.9 MEDIUMAV:L/AC:M/Au:N/C:C/I:C/A:C
- EPSS
- 0.69% probability · 51th percentile
- CISA KEV
- Not listed
- Affected
- rockwellautomation/factorytalk services platform · rockwellautomation/factorytalk view studio
- Source
- ics-cert@hq.dhs.gov
References
- https://ics-cert.us-cert.gov/advisories/ICSA-15-062-02Third Party Advisory, US Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/646323
- https://ics-cert.us-cert.gov/advisories/ICSA-15-062-02Third Party Advisory, US Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/646323
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.