Impact
The FactoryTalk Services Platform does not validate the JSON Web Token (JWT) algorithm during Okta Web Authentication. An attacker can set the algorithm field to "none" and create a forged token that the server accepts as valid. The forged token can impersonate any authorized user, allowing an attacker who already has low‑privilege access to modify system configuration and grant permissions to other systems protected by FTSP. The weakness is a token validation bypass, classified as CWE‑1390.
Affected Systems
All installations of Rockwell Automation FactoryTalk Services Platform may be affected. The version until a patch is applied. No specific version range is listed in the advisory.
Risk and Exploitability
The vulnerability scores a CVSS of 8.8, indicating high severity, while an EPSS score of less than 1% suggests a low likelihood of exploitation in the wild. The flaw is not tracked in the CISA KEV catalog, and an attacker who exploits it can obtain the identity of higher‑privilege accounts and alter configuration or grant permissions to other protected systems.
OpenCVE Enrichment