Vulnerability Description
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk Alarms And Events | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1136876Permissions RequiredVendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1136876Permissions RequiredVendor Advisory
FAQ
What is CVE-2022-38744?
CVE-2022-38744 is a vulnerability with a CVSS score of 7.5 (HIGH). An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. T...
How severe is CVE-2022-38744?
CVE-2022-38744 has been rated HIGH with a CVSS base score of 7.5/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2022-38744?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk Alarms And Events.