CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-10943

CVSS 9.1v4.0pub. 2024-11-12upd. 2026-04-15

An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.

🤖 AI Analysis
How it works

The vulnerability results from the use of shared secrets for authentication between different user accounts. If an attacker is able to enumerate additional information required in the authentication process, they can exploit these shared secrets to impersonate another user. The attack does not require possessing privileges or interaction from the victim, however it requires some preparation in terms of obtaining additional data.

Impact

An attacker can gain unauthorized access to another user's account, leading to breach of confidentiality and integrity of data and resources accessible to that account.

Mitigation & patch

Patches available from the vendor must be applied in accordance with references — detailed recommendations and corrected software versions can be found in the Rockwell Automation security advisory SD1710 available at the address indicated in the references.

Who is affected

Rockwell Automation products indicated in vendor references (specific versions are specified in security advisory SD1710 on the Rockwell Automation website).

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
Auth Bypass
CWE
References