CVE-2023-46290

CVSS V2 None CVSS V3 None
Description
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.
Overview
  • CVE ID
  • CVE-2023-46290
  • Assigner
  • Rockwell
  • Vulnerability Status
  • PUBLISHED
  • Published Version
  • 2023-10-27T18:10:50.923Z
  • Last Modified Date
  • 2023-10-27T18:10:50.923Z
History
Created Old Value New Value Data Type Notes
2024-06-24 23:00:02 Added to TrackCVE