Vulnerabilities > Rockwellautomation > Factorytalk Services Platform > High

DATE CVE VULNERABILITY TITLE RISK
2024-02-16 CVE-2024-21915 Incorrect Permission Assignment for Critical Resource vulnerability in Rockwellautomation Factorytalk Services Platform
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP).
network
low complexity
rockwellautomation CWE-732
8.8
2023-10-27 CVE-2023-46290 Improper Authentication vulnerability in Rockwellautomation Factorytalk Services Platform
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform .
network
high complexity
rockwellautomation CWE-287
8.1
2022-04-01 CVE-2021-32960 Incorrect Authorization vulnerability in Rockwellautomation Factorytalk Services Platform
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name.
network
low complexity
rockwellautomation CWE-863
8.8
2022-02-24 CVE-2020-14478 XXE vulnerability in Rockwellautomation Factorytalk Services Platform
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content.
local
low complexity
rockwellautomation CWE-611
7.1
2020-06-23 CVE-2020-12033 Improper Input Validation vulnerability in Rockwellautomation Factorytalk Services Platform
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
low complexity
rockwellautomation CWE-20
8.8
2019-01-24 CVE-2018-18981 Out-of-bounds Write vulnerability in Rockwellautomation Factorytalk Services Platform
In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial or complete denial-of-service condition to the affected services.
network
low complexity
rockwellautomation CWE-787
7.5