Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2021-32960


Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.


Published

2022-04-01T23:15:09.817

Last Modified

2025-04-17T16:15:23.433

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.5 (HIGH)

CVSSv2 Vector

AV:N/AC:M/Au:S/C:P/I:P/A:P

  • Access Vector: NETWORK
  • Access Complexity: MEDIUM
  • Authentication: SINGLE
  • Confidentiality Impact: PARTIAL
  • Integrity Impact: PARTIAL
  • Availability Impact: PARTIAL
Exploitability Score

6.8

Impact Score

6.4

Weaknesses
  • Type: Primary
    CWE-863
  • Type: Secondary
    CWE-693

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation factorytalk_services_platform ≤ 6.11.00 Yes

References