Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2023-46290


Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.


Published

2023-10-27T19:15:41.560

Last Modified

2024-11-21T08:28:14.440

Status

Modified

Source

[email protected]

Severity

CVSSv3.1: 8.1 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-287
  • Type: Primary
    CWE-287

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation factorytalk_services_platform < 2.80 Yes

References