← Vulnerability feed

Vulnerability record · CVE-2023-2071 · published 12 September 2023

CVE-2023-2071: Rockwellautomation factorytalk view improper input validation vulnerability

Rockwellautomation · Factorytalk View

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

9.8 CVSS 3.1 Critical EPSS 17% · top 3.0% CWE-20 · Improper input validationCWE-434 · Unrestricted file upload
9.8CVSS 3.1 base score
17%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
2References
17 Jun 2026Last modified by NVD

Description

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to execute exported functions from libraries.  There is a routine that restricts it to execute specific functions from two dynamic link library files.  By using a CIP class, an attacker can upload a self-made library to the device which allows the attacker to bypass the security check and execute any code written in the function.

CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2023-2071 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.2CVE-2024-45824Rockwellautomation factorytalk view command injection vulnerabilityCVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command…EPSS 1.3%8.8CVE-2024-4609Rockwellautomation factorytalk view improper input validation vulnerabilityA vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…EPSS 0.65%8.7CVE-2025-9064Rockwellautomation factorytalk view improper authentication vulnerabilityA path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …EPSS 0.61%8.5CVE-2024-7513Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityCVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions…EPSS 1.7%8.5CVE-2024-37369Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityA privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…EPSS 0.33%8.2CVE-2024-37368Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…EPSS 0.50%8.2CVE-2024-37367Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …EPSS 0.50%8.1CVE-2020-12028FactoryTalk View SE remote handlers miss permission checksFactoryTalk View SE remote contains handlers that do not enforce appropriate permissions, allowing an authenticated attacker to interact with data on…EPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2023-2071), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.