Skip to main content
CVE Vulnerability Database
Vulnerability Database/CVE-2024-37369

CVE-2024-37369: FactoryTalk View Privilege Escalation Flaw

CVE-2024-37369 is a privilege escalation vulnerability in Rockwell Automation FactoryTalk View. Low-privilege users can edit scripts and bypass access controls, enabling unauthorized system access and escalation.

Updated:

CVE-2024-37369 Overview

CVE-2024-37369 is a privilege escalation vulnerability affecting Rockwell Automation FactoryTalk View SE. The flaw allows low-privilege users to edit scripts while bypassing Access Control Lists (ACLs). Successful exploitation lets an authenticated local user gain further access within the operator interface and connected industrial control system.

The issue is tracked under CWE-732: Incorrect Permission Assignment for Critical Resource. It carries a CVSS v4.0 base score of 8.5 and requires local access with low privileges. No public proof-of-concept exploit or CISA KEV listing exists at time of writing.

Critical Impact

Low-privilege operators can bypass ACLs to modify HMI scripts, potentially leading to unauthorized changes on production floor visualization and control workflows.

Affected Products

  • Rockwell Automation FactoryTalk View SE
  • Deployments exposing script-editing functionality to non-administrative accounts
  • HMI environments relying on FactoryTalk View SE ACLs for separation of duty

Discovery Timeline

  • 2024-06-14 - CVE-2024-37369 published to NVD
  • 2026-06-17 - Last updated in NVD database

Technical Details for CVE-2024-37369

Vulnerability Analysis

FactoryTalk View SE enforces Access Control Lists to determine which users may create or modify project resources, including VBA-style scripts embedded in HMI displays. The vulnerability breaks this enforcement for the script-editing code path. A user with low privileges can invoke the script editor and persist changes even when the ACL configuration should deny the operation.

Because scripts execute within the FactoryTalk View SE process context, unauthorized modifications can alter alarm handling, tag values, and operator display logic. Attackers with plant-floor access can chain the flaw to influence supervised processes or pivot to accounts that hold higher runtime privileges.

Root Cause

The root cause is incorrect permission assignment on a critical resource [CWE-732]. The script-editing function does not consistently consult the ACL that governs the underlying project component. Authorization checks performed elsewhere in the interface are bypassed when the user reaches the editor through the vulnerable code path.

Attack Vector

Exploitation requires local access to a workstation running FactoryTalk View SE with valid low-privilege credentials. The attacker opens the affected script-editing interface and saves modifications despite lacking the ACL grant. No user interaction from another operator is required. The vulnerability does not require network exposure, which limits mass exploitation but remains relevant for insider threat and post-compromise scenarios.

See the Rockwell Automation Security Advisory SD1674 for vendor-specific technical detail.

Detection Methods for CVE-2024-37369

Indicators of Compromise

  • Unexpected modifications to FactoryTalk View SE project scripts, especially by accounts not designated as engineers or administrators
  • New or altered VBA script content in HMI displays outside of change-management windows
  • FactoryTalk Diagnostics events showing script edits attributed to low-privilege users

Detection Strategies

  • Compare current project scripts against a signed baseline stored in version control to identify unauthorized changes
  • Audit FactoryTalk Directory logs for SaveScript or equivalent editor events tied to non-privileged accounts
  • Correlate Windows process creation events for FactoryTalk View Studio or SE Client with account role assignments

Monitoring Recommendations

  • Forward FactoryTalk Diagnostics and Windows Security logs from HMI workstations to a centralized SIEM for correlation
  • Alert on script modifications occurring outside approved maintenance windows or from unusual user sessions
  • Track logon activity on engineering workstations and flag lateral movement from operator accounts

How to Mitigate CVE-2024-37369

Immediate Actions Required

  • Apply the patched FactoryTalk View SE version referenced in Rockwell Automation Advisory SD1674
  • Inventory accounts with interactive access to HMI workstations and remove unneeded local logon rights
  • Review ACL assignments on FactoryTalk projects and enforce least privilege for script resources

Patch Information

Rockwell Automation has published fixed builds through the vendor advisory. Customers should authenticate to the Rockwell Automation product compatibility and download portal, retrieve the corrected FactoryTalk View SE package, and deploy it during a scheduled maintenance window. Validate HMI functionality against a test project before promoting the patch to production controllers.

Workarounds

  • Restrict interactive logon to FactoryTalk View SE workstations to engineering personnel only until the patch is applied
  • Enforce application allowlisting to block launch of the script editor by non-engineering roles
  • Enable FactoryTalk Diagnostics auditing and require multi-person review of any script change in production
  • Segment HMI networks so that low-privilege operator sessions cannot reach engineering workstations

Disclaimer: This content was generated using AI. While we strive for accuracy, please verify critical information with official sources.

Default Legacy - Prefooter | Experience the World’s Most Advanced Cybersecurity Platform

Experience the Most Advanced Cybersecurity Platform

See how the world’s most intelligent, autonomous cybersecurity platform can protect your organization today and into the future.