← voltar
CVE-2024-21917

Rockwell Automation FactoryTalk® Service Platform Service Token Vulnerability

CVSS 9.8 CRITICALEPSS 0.9%CWE-347
Vexday Risk Score
28Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 9.8EPSS 0.9%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
31 jan 2024Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory.  If exploited, a malicious user could potentially retrieve user information and modify settings without any authentication.
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →