CVE-2024-10945: Rockwell Automation Factorytalk Updater
High severity, CVSS 7.3. EPSS: 0.2% chance of exploitation in the next 30 days.
A Local Privilege Escalation vulnerability exists in the affected product. The vulnerability requires a local, low privileged threat actor to replace certain files during update and exists due to a failure to perform proper security checks before installation.
Affected products
- Rockwell Automation Factorytalk Updater: before 4.20.00 (fixed in 4.20.00)
- Rockwellautomation Factorytalk Updater: from 4.00.00, up to and including 4.20.00
Published 2024-11-12. Last modified 2026-06-17.