Vulnerabilities in PanelView Plus devices could lead to remote code execution
ID: 726c4077-6184-59b6-810f-f8c7b95b9837
STIX ID: report--726c4077-6184-59b6-810f-f8c7b95b9837
Feed Name: Microsoft Security
Threat Score
Microsoft disclosed two vulnerabilities in Rockwell PanelView Plus HMIs—a remote code execution (CVE-2023-2071) and a denial-of-service—rooted in undocumented vendor-specific CIP classes that permit uploading a malicious DLL and invoking exported functions; the report includes protocol analysis, firmware reverse engineering, an exploit proof-of-concept, and mitigation guidance (patches and Defender for IoT detections).
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
