TROYANOSYVIRUS
Retour aux CVEs

CVE-2023-2639

MEDIUM
4.1

Description

The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device.  This may allow a threat actor to craft a malicious website that, when visited, will send a malicious script that can connect to the local WebSocket endpoint and wait for events as if it was a valid client device. If successfully exploited, this would allow a threat actor to receive information including whether FactoryTalk Policy Manager is installed and potentially the entire security policy. 

Details CVE

Score CVSS v3.14.1
SeveriteMEDIUM
Vecteur CVSSCVSS:3.1/AV:N/AC:L/PR:L/UI:R/S:C/C:L/I:N/A:N
Vecteur d'attaqueNETWORK
ComplexiteLOW
Privileges requisLOW
Interaction utilisateurREQUIRED
Publie6/13/2023
Derniere modification11/21/2024
Sourcenvd
Observations honeypot0

Produits affectes

rockwellautomation:factorytalk_policy_managerrockwellautomation:factorytalk_system_services

Faiblesses (CWE)

CWE-346CWE-346

Correlations IOC

Aucune correlation enregistree

This product uses data from the NVD API but is not endorsed or certified by the NVD.