Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2022-38743


Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully exploited, this could allow the attacker to execute arbitrary code and gain access to restricted data.


Published

2022-10-17T21:15:10.343

Last Modified

2025-05-13T15:15:49.180

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-284
  • Type: Primary
    NVD-CWE-Other

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation factorytalk_vantagepoint 8.0 Yes
Application rockwellautomation factorytalk_vantagepoint 8.10 Yes
Application rockwellautomation factorytalk_vantagepoint 8.20 Yes
Application rockwellautomation factorytalk_vantagepoint 8.30 Yes
Application rockwellautomation factorytalk_vantagepoint 8.31 Yes

References