Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

nvd логотип

CVE-2023-2638

Опубликовано: 13 июн. 2023
Источник: nvd
CVSS3: 5.9
CVSS3: 5
EPSS Низкий

Описание

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.

 

Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

Уязвимые конфигурации

Конфигурация 1

Одно из

cpe:2.3:a:rockwellautomation:factorytalk_policy_manager:6.11.0:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:factorytalk_system_services:6.11.0:*:*:*:*:*:*:*

EPSS

Процентиль: 0%
0.00003
Низкий

5.9 Medium

CVSS3

5 Medium

CVSS3

Дефекты

CWE-287
CWE-287

Связанные уязвимости

CVSS3: 5.9
github
больше 2 лет назад

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

CVSS3: 5.9
fstec
больше 2 лет назад

Уязвимость исполняемого файла FTSSBackupRestore.exe программного обеспечения управления производственными процессами FactoryTalk Policy Manager и системной службы FactoryTalk System Services, позволяющая нарушителю загружать вредоносные файлы конфигурации

EPSS

Процентиль: 0%
0.00003
Низкий

5.9 Medium

CVSS3

5 Medium

CVSS3

Дефекты

CWE-287
CWE-287