Successful exploitation of this remotely exploitable vulnerability, discovered by Kaspersky Labs, could result in a denial-of-service condition causing the server to be unavailable.
Rockwell Automation reports this vulnerability affects all versions of FactoryTalk Alarm and Events Server.
In the vulnerability, an unauthenticated attacker with network access to a victim’s Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML.
CVE-2022-38744 is the case number assigned to this vulnerability, which has a CVSS v3 base score of 7.5.
The product sees use in the chemical, critical manufacturing, food and agriculture, and water and wastewater systems sectors. It also sees action on a global basis.
No known public exploits specifically target this vulnerability. This vulnerability has a low attack complexity.
Rockwell recommends users of the affected software set up IPsec to mitigate this issue as detailed in the deploying FactoryTalk software with IPsec Knowledgebase article. Customers are also directed towards general risk mitigation strategies provided in the Recommended Security Guidelines Knowledgebase Article.
For more information, click on Rockwell Automation’s Security advisory.

