VYPR

FactoryTalk® ViewPoint

by Rockwellautomation

CVEs (5)

  • CVE-2025-9066HigOct 14, 2025
    risk 0.57cvss epss 0.00

    A security issue was discovered within FactoryTalk® ViewPoint, allowing unauthenticated attackers to achieve XXE. Certain SOAP requests can be abused to perform XXE, resulting in a temporary denial-of-service.

  • CVE-2025-7973HigAug 14, 2025
    risk 0.55cvss epss 0.00

    A security issue exists in FactoryTalk ViewPoint version 14.0 or below due to improper handling of MSI repair operations. During a repair, attackers can hijack the cscript.exe console window, which runs with SYSTEM privileges. This can be exploited to spawn an elevated command…

  • CVE-2023-2444May 11, 2023
    risk 0.00cvss epss 0.00

    A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user…

  • CVE-2022-3158Oct 17, 2022
    risk 0.00cvss epss 0.03

    Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end…

  • CVE-2022-38743Oct 17, 2022
    risk 0.00cvss epss 0.01

    Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the…