An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
The vulnerability (CWE-522 — Insufficiently Protected Credentials) results from the use of a weak encryption algorithm or mechanism for storing user application passwords. An attacker who gains access to encrypted authentication data can – due to the weakness of the applied method – reverse or break the encryption and recover passwords in plain text. This process does not require authentication or user interaction, making the attack possible to conduct remotely.
An attacker can extract passwords of other users of the FactoryTalk® AssetCentre application, which may lead to unauthorized access to the industrial asset management system and potential compromise of confidentiality, integrity, and availability of data in the OT environment.
Update Rockwell Automation FactoryTalk® AssetCentre software to version V15.00.001 or later. Detailed information is available in the manufacturer's security bulletin at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1721.html
All versions of Rockwell Automation FactoryTalk® AssetCentre prior to V15.00.001
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:XRockwellautomation Factorytalk Assetcentre
APPRockwellautomation< 15.00.01
Related vulnerabilities
RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre
SQLi bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre
RCE przez niebezpieczną deserializację w Rockwell FactoryTalk AssetCentre
SQL Injection bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre
Niebezpieczna deserializacja w Rockwell FactoryTalk AssetCentre — pełny dostęp bez uwierzytelnienia