This content is restricted.
Brief
Summary:
The document discusses a critical vulnerability in Rockwell Automation's FactoryTalk Service Platform, carrying a CVSS v3 score of 9.8. The vulnerability, CVE-2024-21917, allows a malicious user to obtain the service token and use it for authentication, enabling them to retrieve user information and modify settings without authentication. The affected products are FactoryTalk Service Platform versions prior to v6.4. The recommended mitigation is to set DCOM authentication level to 6 or enable verification of the publisher information of any executable attempting to use the FactoryTalk Services APIs. Additionally, CISA recommends implementing defensive measures to minimize the risk of exploitation, such as minimizing network exposure, isolating control systems, and using secure remote access methods. No public exploitation of this vulnerability has been reported.
Highlights content goes here...
This content is restricted.
