Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2021-32960

Опубликовано: 01 апр. 2022
Источник: nvd
CVSS3: 8.5
CVSS3: 8.8
CVSS2: 6
EPSS Низкий

Описание

Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.

Ссылки

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*
Версия до 6.11.00 (включая)

EPSS

Процентиль: 10%
0.00036
Низкий

8.5 High

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-863
CWE-693

Связанные уязвимости

CVSS3: 8.8
github
почти 4 года назад

Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have the same privileges as if they were logged on to the client machine.

CVSS3: 8.8
fstec
больше 4 лет назад

Уязвимость службы FactoryTalk Security платформы управления производственными процессами FactoryTalk Services Platform, позволяющая нарушителю обойти ограничения безопасности и повысить свои привилегии

EPSS

Процентиль: 10%
0.00036
Низкий

8.5 High

CVSS3

8.8 High

CVSS3

6 Medium

CVSS2

Дефекты

CWE-863
CWE-693