CVE-2024-3640: Rockwell Automation Factorytalk Remote Access
High severity, CVSS 7.0. EPSS: 0.3% chance of exploitation in the next 30 days.
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
Affected products
- Rockwell Automation Factorytalk Remote Access: version v13.5.0.174 only
Published 2024-05-16. Last modified 2026-06-17.