CVE-2024-21915

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_services_platform:*:*:*:*:*:*:*:*

History

No history.

Information

Published : 2024-02-16 19:15

Updated : 2024-12-11 19:31


NVD link : CVE-2024-21915

Mitre link : CVE-2024-21915

CVE.ORG link : CVE-2024-21915


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_services_platform
CWE
CWE-732

Incorrect Permission Assignment for Critical Resource