Microsoft Uncovers Critical Flaws in Rockwell Automation PanelView Plus
ID: 61a6b8ba-d9d9-51b5-9c28-91555be0aca2
STIX ID: report--61a6b8ba-d9d9-51b5-9c28-91555be0aca2
Feed Name: The Hacker News
**Executive summary:** Microsoft and security researchers disclosed two critical Rockwell Automation flaws—CVE-2023-2071 (RCE, CVSS 9.8) and CVE-2023-29464 (memory disclosure/DoS, CVSS 8.2)—impacting PanelView Plus and FactoryTalk components and enabling unauthenticated remote code execution, information disclosure, or denial-of-service; Rockwell and CISA advisories were published in Sept/Oct 2023. The report also highlights that attackers are actively exploiting a separate HFS template-injection vulnerability (CVE-2024-23692) to deliver cryptocurrency miners and trojans (e.g., Xeno RAT, Gh0st RAT, PlugX, GoThief), illustrating ongoing malware campaigns against exposed infrastructure.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
