PT-2021-9728 · Rockwell Automation · Factorytalk Services Platform

Published

2021-03-18

·

Updated

2021-03-26

·

CVE-2020-14516

CVSS v3.1

10

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions Rockwell Automation FactoryTalk Services Platform versions 6.10.00 through 6.11.00
Description The issue is related to the implementation of the SHA-256 hashing algorithm in the FactoryTalk Services Platform, which prevents user passwords from being hashed properly. This affects the security of user passwords.
Recommendations For versions 6.10.00 and 6.11.00, consider temporarily disabling password hashing until a proper fix is available. Restrict access to sensitive areas of the platform to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

CVE-2020-14516

Affected Products

Factorytalk Services Platform