CVE-2024-21915

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*

History

11 Dec 2024, 19:31

Type Values Removed Values Added
CPE cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*
References () https://www.rockwellautomation.com/en-us/support/advisory.SD1662.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD1662.html - Broken Link, Vendor Advisory
First Time Rockwellautomation
Rockwellautomation factorytalk Services Platform

21 Nov 2024, 08:55

Type Values Removed Values Added
References () https://www.rockwellautomation.com/en-us/support/advisory.SD1662.html - () https://www.rockwellautomation.com/en-us/support/advisory.SD1662.html -
Summary
  • (es) Existe una vulnerabilidad de escalada de privilegios en Rockwell Automation FactoryTalk® Service Platform (FTSP). Si se explota, un usuario malintencionado con privilegios básicos de grupo de usuarios podría iniciar sesión en el software y recibir privilegios de grupo de administrador FTSP. Un actor de amenazas podría potencialmente leer y modificar datos confidenciales, eliminar datos y hacer que el sistema FTSP no esté disponible.

16 Feb 2024, 19:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-02-16 19:15

Updated : 2024-12-11 19:31


NVD link : CVE-2024-21915

Mitre link : CVE-2024-21915

CVE.ORG link : CVE-2024-21915


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_services_platform
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource