CVE-2017-14022
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (4.22%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
An Improper Input Validation issue was discovered in Rockwell Automation FactoryTalk Alarms and Events, Version 2.90 and earlier. An unauthenticated attacker with remote access to a network with FactoryTalk Alarms and Events can send a specially crafted set of packets packet to Port 403/TCP (the history archiver service), causing the service to either stall or terminate.
- CVSS 3.0
- 7.5 HIGHCVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H
- EPSS
- 4.22% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-20
- Affected
- rockwellautomation/factorytalk alarms and events
- Source
- ics-cert@hq.dhs.gov
References
- http://www.securityfocus.com/bid/102114Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-341-02Third Party Advisory, US Government Resource
- http://www.securityfocus.com/bid/102114Third Party Advisory, VDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-341-02Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.