Vulnerability Description
Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious executable. This may allow an authorized, but not privileged local user to execute arbitrary code with elevated privileges on the system. CVSS v3 base score: 8.8, CVSS vector string: (AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:H/A:H). Rockwell Automation has released a new version of FactoryTalk Activation, Version 4.01, which addresses the identified vulnerability. Rockwell Automation recommends upgrading to the latest version of FactoryTalk Activation, Version 4.01 or later.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk Activation | <= 4.00.02 |
Related Weaknesses (CWE)
References
- http://www.securityfocus.com/bid/96996Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-047-02Third Party AdvisoryUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/939382Permissions RequiredVendor Advisory
- http://www.securityfocus.com/bid/96996Third Party AdvisoryVDB Entry
- https://ics-cert.us-cert.gov/advisories/ICSA-17-047-02Third Party AdvisoryUS Government Resource
- https://rockwellautomation.custhelp.com/app/answers/detail/a_id/939382Permissions RequiredVendor Advisory
FAQ
What is CVE-2017-6015?
CVE-2017-6015 is a vulnerability with a CVSS score of 7.8 (HIGH). Without quotation marks, any whitespace in the file path for Rockwell Automation FactoryTalk Activation version 4.00.02 remains ambiguous, which may allow an attacker to link to or run a malicious exe...
How severe is CVE-2017-6015?
CVE-2017-6015 has been rated HIGH with a CVSS base score of 7.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2017-6015?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk Activation.