CVE-2024-6326

July 16, 2024, 6 p.m.

Undergoing Analysis
CVE has been marked for Analysis. Normally once in this state the CVE will be analyzed by NVD staff within 24 hours.

Products

Rockwell Automation FactoryTalk System Service

Source

PSIRT@rockwellautomation.com

Tags

CVE-2024-6326 details

Published : July 16, 2024, 5:15 p.m.
Last Modified : July 16, 2024, 6 p.m.

Description

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.

CVSS Score

1 2 3 4 5 6 7 8 9 10

Weakness

Weakness Name Description
CWE-269 Improper Privilege Management The product does not properly assign, modify, track, or check privileges for an actor, creating an unintended sphere of control for that actor.
This website uses the NVD API, but is not approved or certified by it.