You are here

Rockwell Automation FactoryTalk Diagnostics (ICSA-20-051-02) – Product Used in the Water and Wastewater Sector

Rockwell Automation FactoryTalk Diagnostics (ICSA-20-051-02) – Product Used in the Water and Wastewater Sector

Created: Friday, February 21, 2020 - 15:08
Categories:
Cybersecurity

CISA has published an advisory on a deserialization of untrusted data vulnerability in Rockwell Automation Factory Talk Diagnostics. All versions are affected. Successful exploitation of this vulnerability could allow a remote unauthenticated attacker to execute arbitrary code with SYSTEM level privileges. Rockwell Automation is currently working to develop updated software that addresses the reported vulnerability. Rockwell Automation recommends affected users implement the compensating controls, based on their needs. CISA also recommends a series of measures to mitigate the vulnerability. Read the advisory at CISA.