← Vulnerability feed

Vulnerability record · CVE-2024-7513 · published 14 August 2024

CVE-2024-7513: Rockwellautomation factorytalk view incorrect permission assignment vulnerability

Rockwellautomation · Factorytalk View

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.

8.5 CVSS 4.0 High EPSS 1.7% · top 24.4% CWE-732 · Incorrect permission assignment
8.5CVSS 4.0 base score
1.7%EPSS exploitation probability, 30 days
NoNot in CISA KEV
1Affected product versions listed by NVD
1References
17 Jun 2026Last modified by NVD

Description

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.

CVSS:4.0/AV:L/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:

Affected products

1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.

References

Track CVE-2024-7513 inside VULONE

Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.

Start free Open in platform

Related vulnerabilities

Same products first, then exploited flaws of the same weakness class.

9.8CVE-2023-2071Rockwellautomation factorytalk view improper input validation vulnerabilityRockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…EPSS 17%9.2CVE-2024-45824Rockwellautomation factorytalk view command injection vulnerabilityCVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command…EPSS 1.3%8.8CVE-2024-4609Rockwellautomation factorytalk view improper input validation vulnerabilityA vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…EPSS 0.65%8.7CVE-2025-9064Rockwellautomation factorytalk view improper authentication vulnerabilityA path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device …EPSS 0.61%8.5CVE-2024-37369Rockwellautomation factorytalk view incorrect permission assignment vulnerabilityA privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…EPSS 0.33%8.2CVE-2024-37368Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…EPSS 0.50%8.2CVE-2024-37367Rockwellautomation factorytalk view improper authentication vulnerabilityA user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …EPSS 0.50%8.1CVE-2020-12028FactoryTalk View SE remote handlers miss permission checksFactoryTalk View SE remote contains handlers that do not enforce appropriate permissions, allowing an authenticated attacker to interact with data on…EPSS 53%analysed

Source: NIST National Vulnerability Database (record CVE-2024-7513), CISA KEV, FIRST EPSS (scores of 2026-09-26). This page is refreshed as NVD updates the record.