Rockwell Automation FactoryTalk System Services Vulnerable To Use Of Hard-Coded Cryptographic Key
CVE-2023-2637
8.2HIGH
Key Information:
- Vendor
Rockwell Automation
- Vendor
- CVE Published:
- 13 June 2023
What is CVE-2023-2637?
Rockwell Automation's FactoryTalk System Services has a security flaw stemming from the use of a hard-coded cryptographic key for generating administrator cookies. This issue potentially allows a local, authenticated non-admin user to create an invalid administrator cookie, granting elevated privileges to the FactoryTalk Policy Manager database. Exploiting this vulnerability could enable a malicious actor to implement unauthorized changes to the database, which could affect the deployment of security policy models by legitimate FactoryTalk Policy Manager users. Successful exploitation requires user interaction, making it a critical focus area for security management.
Affected Version(s)
FactoryTalk System Services <= 6.20