ZeroHour

CVE-2024-7956

moderate

Improper Authentication in Rockwell Automation FactoryTalk Optix

CVSS 4.0
7.6 high
EPSS
<1%p18
Published
()
Modified
AI analysis

CVE-2024-7956 is an improper authentication flaw (CWE-287) in Rockwell Automation's FactoryTalk Optix in which user-to-project access is not correctly enforced, letting a threat actor reach other users' projects. It is triggered remotely over the network (AV:N) by an attacker who already holds basic, low-privilege user credentials, with no user interaction required. If exploited, the attacker can view, modify, and delete projects they should not be able to access, producing high confidentiality and integrity impact on the affected system but no availability loss and no impact on other systems. Affected are organizations running the affected Rockwell Automation products, particularly multi-user deployments where basic users connect to shared projects over the network. There is no known exploitation in the wild, no public proof-of-concept, and no entry in CISA KEV (EPSS ~0.3%).

What to do: Upgrade FactoryTalk Optix to the patched release identified in Rockwell Automation's security advisory (specific version numbers are not provided in the source data). Until patched, restrict network access to affected instances, limit which basic-privilege accounts can connect, and review project audit logs for unexpected modifications or deletions performed by low-privilege users.

Affected
Rockwell Automation FactoryTalk Optix
Estimated exposure
moderate≈10,000–100,000 installations/developer seats (order-of-magnitude estimate; no public install counts) — Inferred from Rockwell Automation's large installed base and FactoryTalk Optix's role as the vendor's newer HMI/design platform, with actual exposure limited to networked instances that have multiple basic-privilege users; the source data…

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A vulnerability exists in the affected products that allows a threat actor to gain access to user’s projects. To exploit this vulnerability the threat actor must have basic user privileges. If exploited, the threat actor can modify and delete the project.

Weakness
CWE-287
Vector
CVSS:4.0/AV:N/AC:L/AT:P/PR:L/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.