Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2444

Опубликовано: 11 мая 2023
Источник: nvd
CVSS3: 7.1
CVSS3: 8.8
EPSS Низкий

Описание

A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.

Уязвимые конфигурации

Конфигурация 1
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:*:*:*:*:*:*:*:*
Версия до 8.40 (исключая)

EPSS

Процентиль: 32%
0.00125
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352

Связанные уязвимости

CVSS3: 7.1
github
больше 2 лет назад

A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.

CVSS3: 8.8
fstec
больше 2 лет назад

Уязвимость программное обеспечение для собора данных FactoryTalk VantagePoint, связанная с подделкой межсайтовых запросов, позволяющая нарушителю осуществить межсайтовую подделку запросов

EPSS

Процентиль: 32%
0.00125
Низкий

7.1 High

CVSS3

8.8 High

CVSS3

Дефекты

CWE-352