CVE-2014-9209 is an untrusted search path vulnerability affecting Rockwell Automation FactoryTalk Services Platform before version 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier. This flaw allows a local attacker to gain privileges by placing a malicious DLL in an unspecified directory, which the Clean Utility application then loads. With a CVSS score of 6.9, this vulnerability has a medium attack complexity and could lead to complete compromise of confidentiality, integrity, and availability. There is no public exploit code available (Metasploit, Nuclei, ExploitDB), it is not listed in CISA's KEV catalog, and while there is some community discussion and media coverage, it is not considered actively exploited.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.70.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:* | ||
<= 8.00.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:factorytalk_view_studio:*:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:L/AC:M/Au:N/C:C/I:C/A:C
No social media mentions found for this CVE.
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.0 Bluesky, 0.0 Mastodon, and 0.1 GitHub mentions.
The average CVE in this peer group has 0.0 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.