In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:H/A:HRockwellautomation Factorytalk Services Platform
APPRockwellautomation6.10.006.11.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
CWE
Related vulnerabilities
CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product
Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix
CVE-2024-21915CRITICAL9.0PL ✓same product
Privilege escalation w Rockwell Automation FactoryTalk Services Platform
CVE-2024-21917CRITICAL9.8PL ✓same product
Rockwell Automation FactoryTalk — przechwycenie tokenu uwierzytelniającego (brak podpisu cyfrowego)
CVE-2020-6967CRITICAL9.8PL ✓same product
Niebezpieczna deserializacja w Rockwell FactoryTalk Diagnostics (port TCP/8082)
CVE-2023-46290HIGH8.1same product
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Wind...