CVE-2022-3158
 
Severity Score
Exploit Likelihood
Affected Versions
Public Exploits
0Exploited in Wild
-Decision
Descriptions
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could allow a user with basic user privileges to perform remote code execution on the server.
Rockwell Automation FactoryTalk VantagePoint versiones 8.0, 8.10, 8.20, 8.30 y 8.31, son vulnerables a una vulnerabilidad de comprobación de entrada. El servidor SQL de FactoryTalk VantagePoint carece de comprobación de entrada cuando los usuarios introducen sentencias SQL para recuperar información de la base de datos del back-end. Si es explotado con éxito, esto podría permitir a un usuario con privilegios de usuario básicos llevar a cabo una ejecución de código remota en el servidor
CVSS Scores
SSVC
- Decision:-
Timeline
- 2022-09-07 CVE Reserved
- 2022-10-17 CVE Published
- 2024-08-03 CVE Updated
- 2024-10-01 EPSS Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-89: Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
CAPEC
References (0)
URL | Tag | Source |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Vantagepoint Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" | 8.0 Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" and version "8.0" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Vantagepoint Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" | 8.10 Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" and version "8.10" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Vantagepoint Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" | 8.20 Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" and version "8.20" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Vantagepoint Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" | 8.30 Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" and version "8.30" | - |
Affected
| ||||||
Rockwellautomation Search vendor "Rockwellautomation" | Factorytalk Vantagepoint Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" | 8.31 Search vendor "Rockwellautomation" for product "Factorytalk Vantagepoint" and version "8.31" | - |
Affected
|