CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2024-21915

CVSS 9.0v3.1pub. 2024-02-16upd. 2024-12-11

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.

🤖 AI Analysis
How it works

An attacker with an account in the FTSP basic user group can log into the software and, as a result of improperly configured permissions (CWE-732), obtain FTSP administrator group privileges. The mechanism does not require victim interaction or high input privileges, but does require a certain level of attack complexity (AC:H). After privilege escalation, the attacker operates in an extended security context that goes beyond the scope of the originally granted account.

Impact

An attacker can read and modify sensitive data, delete data, and cause the FTSP system to become unavailable, which in an industrial environment may result in disruption of production or operational processes.

Mitigation & patch

Apply patches available from the manufacturer according to the references — detailed instructions are contained in Rockwell Automation advisory SD1662 available at: https://www.rockwellautomation.com/en-us/support/advisory.SD1662.html

Who is affected

Rockwell Automation FactoryTalk® Service Platform (FTSP) — versions indicated in the manufacturer's references (advisory SD1662)

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:C/C:H/I:H/A:H
  • Rockwellautomation Factorytalk Services Platform

    APP
    Rockwellautomation
    < 2.74
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
Tags
LPE
CWE
References

Related vulnerabilities

CVE-2021-22681CRITICAL9.8⚠ KEVPL ✓same product

Rockwell Automation — pominięcie weryfikacji klucza uwierzytelnienia w sterownikach Logix

CVE-2024-21917CRITICAL9.8PL ✓same product

Rockwell Automation FactoryTalk — przechwycenie tokenu uwierzytelniającego (brak podpisu cyfrowego)

CVE-2020-14516CRITICAL10.0PL ✓same product

Błędna implementacja SHA-256 w Rockwell FactoryTalk Services Platform

CVE-2020-6967CRITICAL9.8PL ✓same product

Niebezpieczna deserializacja w Rockwell FactoryTalk Diagnostics (port TCP/8082)

CVE-2023-46290HIGH8.1same product

Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Wind...