CVE-2025-24481 Details
Description
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.
A vulnerability exists in FactoryTalk View Site Edition versions prior to 15.0, as well as in versions 12, 13, and 14 of the same product. This vulnerability is due to incorrect permissions assigned to the remote debugger port, which can lead to unauthenticated access to the system configuration.
Users are advised to upgrade to version 15.0 or apply the patch available for version 14. For versions 12, 13, and 14, the specific patch information can be found in Rockwell Automation's Answer ID 1152304. Additionally, it is recommended to protect physical access to the workstation and restrict access to port 8091 at the network or workstation level.
Metrics
CVSS 4.0 Severity and Vector Strings:
CVSS 3.x Severity and Vector Strings:
No data available for CVSS Version 2.0 on this CVE.
Volerion
Assessed Jan 28, 2025CISA-ADP
Assessed Jan 28, 2025References to Advisories, Solutions, and Tools
By selecting these links, you will be leaving this site. These are references gathered from the official CVE record and are not endorsed by Volerion.
| URL | Source(s) | Tag(s) |
|---|---|---|
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1720.html | [email protected] | AdvisoryBundleRemedyVendor |
Weakness Enumeration
| CWE-ID | CWE Name | Source |
|---|---|---|
| CWE-732 | Incorrect Permission Assignment for Critical Resource | [email protected] |
Affected Products
| Product | Versions |
|---|---|
| Rockwell Automation FactoryTalk View SE | All versions |
CPE
Remediation
| |
Change History
3 change records found show changes
| Date | Action | Recorded By |
|---|---|---|
| Jun 17, 2026 | CVE Modified | [email protected] |
| Jun 17, 2026 | CVE Modified | CISA-ADP |
| Jan 28, 2025 | New CVE Received | [email protected] |
Volerion