FactoryTalk Fiasco: Critical Security Flaw Puts Industrial Control Systems at Risk
Attention FactoryTalk users: A CVSS v4.0 score of 8.5 vulnerability allows unauthorized file edits, triggering code execution with elevated permissions. Rockwell Automation urges immediate security updates and best practices to mitigate risks.

Hot Take:
“Rockwell Automation: Where even your grandma can become a hacker with just a pinch of permissions mismanagement!”
Key Points:
- Critical vulnerability (CVSS v4 8.5) in Rockwell Automation’s FactoryTalk View Site Edition.
- Easy-to-exploit flaw due to incorrect permission assignments.
- Allows any user to edit or replace files executed with elevated permissions.
- Affects FactoryTalk version 13.0 and FactoryTalk View SE version 13.0.
- Mitigation steps include tightening folder permissions and following security best practices.
Already a member? Log in here