Vulnerabilities > Rockwellautomation > Factorytalk Policy Manager > High

DATE CVE VULNERABILITY TITLE RISK
2023-06-13 CVE-2023-2637 Use of Hard-coded Credentials vulnerability in Rockwellautomation products
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them administrative privileges to the FactoryTalk Policy Manger database.
local
low complexity
rockwellautomation CWE-798
8.2