Vulnerability Description
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.
CVSS Score
CRITICAL
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk Services Platform | < 2.74 |
Related Weaknesses (CWE)
References
- https://www.rockwellautomation.com/en-us/support/advisory.SD1662.htmlBroken LinkVendor Advisory
- https://www.rockwellautomation.com/en-us/support/advisory.SD1662.htmlBroken LinkVendor Advisory
FAQ
What is CVE-2024-21915?
CVE-2024-21915 is a vulnerability with a CVSS score of 9.0 (CRITICAL). A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into th...
How severe is CVE-2024-21915?
CVE-2024-21915 has been rated CRITICAL with a CVSS base score of 9.0/10. This is considered a critical vulnerability requiring immediate attention.
Is there a patch for CVE-2024-21915?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Factorytalk Services Platform.