Логотип exploitDog
bind:CVE-2023-2638
Консоль
Логотип exploitDog

exploitDog

bind:CVE-2023-2638

Количество 3

Количество 3

nvd логотип

CVE-2023-2638

больше 2 лет назад

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

CVSS3: 5.9
EPSS: Низкий
github логотип

GHSA-7j8r-p4gv-87r9

больше 2 лет назад

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

CVSS3: 5.9
EPSS: Низкий
fstec логотип

BDU:2023-03935

больше 2 лет назад

Уязвимость исполняемого файла FTSSBackupRestore.exe программного обеспечения управления производственными процессами FactoryTalk Policy Manager и системной службы FactoryTalk System Services, позволяющая нарушителю загружать вредоносные файлы конфигурации

CVSS3: 5.9
EPSS: Низкий

Уязвимостей на страницу

Уязвимость
CVSS
EPSS
Опубликовано
nvd логотип
CVE-2023-2638

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
github логотип
GHSA-7j8r-p4gv-87r9

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local, authenticated non-admin user to craft a malicious backup archive, without password protection, that will be loaded by FactoryTalk System Services as a valid backup when a restore procedure takes places. User interaction is required for this vulnerability to be successfully exploited.

CVSS3: 5.9
0%
Низкий
больше 2 лет назад
fstec логотип
BDU:2023-03935

Уязвимость исполняемого файла FTSSBackupRestore.exe программного обеспечения управления производственными процессами FactoryTalk Policy Manager и системной службы FactoryTalk System Services, позволяющая нарушителю загружать вредоносные файлы конфигурации

CVSS3: 5.9
0%
Низкий
больше 2 лет назад

Уязвимостей на страницу