Rockwell Automation FactoryTalk Services Platform
Summary
A security vulnerability has been identified in Rockwell Automation FactoryTalk Services Platform (FTSP) version 6.60. The flaw allows an attacker to bypass JWT signature validation, enabling them to impersonate authorized users and gain unauthorized access to system configurations.
IFF Assessment
This vulnerability allows for unauthorized access and system configuration manipulation, representing a significant risk to defenders.
Severity
The CVSS score of 7.8 reflects a high severity, indicating that the vulnerability can be exploited with low complexity and grants high privileges. The attack vector is network-based, and the impact on confidentiality, integrity, and availability is significant.
Defender Context
This vulnerability in Rockwell Automation's FactoryTalk Services Platform affects critical manufacturing infrastructure and has a worldwide deployment. Defenders should prioritize patching or applying mitigations to affected systems to prevent unauthorized access and impersonation attacks.