// For flags

CVE-2023-2639

Rockwell Automation FactoryTalk System Services Vulnerable to Sensitive Information Disclosure

Severity Score

4.7
*CVSS v3.1

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

-
*SSVC
Descriptions

The underlying feedback mechanism of

Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device.  This may allow a threat actor to craft a malicious website that, when visited, will send a malicious script that can connect to the local WebSocket endpoint and wait for events as if it was a valid client device. If successfully exploited, this would allow a threat actor to receive information including whether FactoryTalk Policy Manager is installed and potentially the entire security policy.

*Credits: Sharon Brizinov of Claroty Research - Team82
CVSS Scores
Attack Vector
Network
Attack Complexity
Low
Privileges Required
None
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
Attack Vector
Network
Attack Complexity
Low
Privileges Required
Low
User Interaction
Required
Scope
Changed
Confidentiality
Low
Integrity
None
Availability
None
* Common Vulnerability Scoring System
SSVC
  • Decision:-
Exploitation
-
Automatable
-
Tech. Impact
-
* Organization's Worst-case Scenario
Timeline
  • 2023-05-10 CVE Reserved
  • 2023-06-13 CVE Published
  • 2024-08-02 CVE Updated
  • 2024-11-23 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-346: Origin Validation Error
CAPEC
  • CAPEC-466: Leveraging Active Adversary in the Middle Attacks to Bypass Same Origin Policy
References (0)
URL Tag Source
URL Date SRC
URL Date SRC
URL Date SRC
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rockwellautomation
Search vendor "Rockwellautomation"
Factorytalk Policy Manager
Search vendor "Rockwellautomation" for product "Factorytalk Policy Manager"
6.11.0
Search vendor "Rockwellautomation" for product "Factorytalk Policy Manager" and version "6.11.0"
-
Affected
Rockwellautomation
Search vendor "Rockwellautomation"
Factorytalk System Services
Search vendor "Rockwellautomation" for product "Factorytalk System Services"
6.11.0
Search vendor "Rockwellautomation" for product "Factorytalk System Services" and version "6.11.0"
-
Affected