CVE-2023-2639

The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device.  This may allow a threat actor to craft a malicious website that, when visited, will send a malicious script that can connect to the local WebSocket endpoint and wait for events as if it was a valid client device. If successfully exploited, this would allow a threat actor to receive information including whether FactoryTalk Policy Manager is installed and potentially the entire security policy. 
References
Link Resource
https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139683 Permissions Required Vendor Advisory
Configurations

Configuration 1 (hide)

OR cpe:2.3:a:rockwellautomation:factorytalk_policy_manager:6.11.0:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:factorytalk_system_services:6.11.0:*:*:*:*:*:*:*

History

26 Jun 2023, 16:22

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 4.7
CPE cpe:2.3:a:rockwellautomation:factorytalk_system_services:6.11.0:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:factorytalk_policy_manager:6.11.0:*:*:*:*:*:*:*
References (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139683 - (MISC) https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139683 - Permissions Required, Vendor Advisory
First Time Rockwellautomation
Rockwellautomation factorytalk System Services
Rockwellautomation factorytalk Policy Manager
CWE CWE-346

13 Jun 2023, 21:27

Type Values Removed Values Added
New CVE

Information

Published : 2023-06-13 21:15

Updated : 2023-12-10 15:01


NVD link : CVE-2023-2639

Mitre link : CVE-2023-2639

CVE.ORG link : CVE-2023-2639


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_system_services
  • factorytalk_policy_manager
CWE
CWE-346

Origin Validation Error