authentication bypass vulnerability exists in the affected product. The
vulnerability exists due to shared secrets across accounts and could allow a threat
actor to impersonate a user if the threat actor is able to enumerate additional
information required during authentication.
No analysis available yet.
Vendor Solution
Upgrade to V4.20.00
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-33359 | An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication. |
Wed, 13 Nov 2024 18:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation factorytalk Updater |
|
| CPEs | cpe:2.3:a:rockwellautomation:factorytalk_updater:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rockwellautomation
Rockwellautomation factorytalk Updater |
|
| Metrics |
ssvc
|
Tue, 12 Nov 2024 17:15:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication. | |
| Title | FactoryTalk® Updater Authentication Bypass | |
| Weaknesses | CWE-922 | |
| References |
| |
| Metrics |
cvssV3_1
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-11-13T17:33:27.816Z
Reserved: 2024-11-06T20:19:53.998Z
Link: CVE-2024-10943
Updated: 2024-11-13T17:33:11.064Z
Status : Awaiting Analysis
Published: 2024-11-12T17:15:06.147
Modified: 2024-11-13T17:01:58.603
Link: CVE-2024-10943
No data.
OpenCVE Enrichment
No data.
EUVD