An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.
The vulnerability results from the use of shared secrets for authentication between different user accounts. If an attacker is able to enumerate additional information required in the authentication process, they can exploit these shared secrets to impersonate another user. The attack does not require possessing privileges or interaction from the victim, however it requires some preparation in terms of obtaining additional data.
An attacker can gain unauthorized access to another user's account, leading to breach of confidentiality and integrity of data and resources accessible to that account.
Patches available from the vendor must be applied in accordance with references — detailed recommendations and corrected software versions can be found in the Rockwell Automation security advisory SD1710 available at the address indicated in the references.
Rockwell Automation products indicated in vendor references (specific versions are specified in security advisory SD1710 on the Rockwell Automation website).
CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X