PT-2024-6220 · Rockwell Automation · Factorytalk Batch View

Published

2024-09-12

·

Updated

2024-10-02

·

CVE-2024-45823

CVSS v3.1

9.8

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions FactoryTalk Batch View (affected versions not specified)
Description The issue is related to an authentication bypass vulnerability. This vulnerability exists due to shared secrets across accounts, which could allow a threat actor to impersonate a user if they can enumerate additional information required during authentication. The vulnerability may be exploited by a remote attacker to bypass existing security restrictions.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Authentication

Weakness Enumeration

Related Identifiers

BDU:2024-07161
CVE-2024-45823

Affected Products

Factorytalk Batch View