CVE-2022-3158
Summary
| CVE | CVE-2022-3158 |
|---|---|
| State | PUBLIC |
| Assigner | [email protected] |
| Source Priority | CVE Program / NVD first with legacy fallback |
| Published | 2022-10-17 22:15:00 UTC |
| Updated | 2022-10-20 14:42:00 UTC |
| Description | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server. |
Risk And Classification
Problem Types: CWE-89
NVD Known Affected Configurations (CPE 2.3)
| Type | Vendor | Product | Version | Update | Edition | Language |
|---|---|---|---|---|---|---|
| Application | Rockwellautomation | Factorytalk Vantagepoint | 8.0 | All | All | All |
| Application | Rockwellautomation | Factorytalk Vantagepoint | 8.10 | All | All | All |
| Application | Rockwellautomation | Factorytalk Vantagepoint | 8.20 | All | All | All |
| Application | Rockwellautomation | Factorytalk Vantagepoint | 8.30 | All | All | All |
| Application | Rockwellautomation | Factorytalk Vantagepoint | 8.31 | All | All | All |
References
| Reference | Source | Link | Tags |
|---|---|---|---|
| Factory Talk VantagePoint Software Broken Access Control and Input Validation Vulnerability | MISC | rockwellautomation.custhelp.com | |
| CVE Program record | CVE.ORG | www.cve.org | canonical |
| NVD vulnerability detail | NVD | nvd.nist.gov | canonical, analysis |
No vendor comments have been submitted for this CVE.
There are currently no legacy QID mappings associated with this CVE.