A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.

Advisories
Source ID Title
EUVD EUVD EUVD-2023-33929 A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product.  Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.
Fixes

Solution

Customers should upgrade to version 8.40 to fix the issue.


Workaround

No workaround given by the vendor.

History

Fri, 24 Jan 2025 22:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-01-24T21:16:59.768Z

Reserved: 2023-05-01T13:53:26.441Z

Link: CVE-2023-2444

cve-icon Vulnrichment

Updated: 2024-08-02T06:26:08.927Z

cve-icon NVD

Status : Modified

Published: 2023-05-11T19:15:09.437

Modified: 2024-11-21T07:58:37.733

Link: CVE-2023-2444

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.