news.mlab.sh
Back to the feed
vulnerability

Rockwell Automation FactoryTalk Activation Manager

HighCVSS 8.5
Summary

Rockwell Automation has released an advisory regarding a critical privilege escalation vulnerability in FactoryTalk Activation Manager. Versions V5.02 and below are affected, allowing an attacker with Windows credentials to gain SYSTEM-level access to files, processes, and system resources. Rockwell Automation recommends updating to version V5.03 to mitigate the risk.

Rockwell Automation has released an advisory regarding a critical privilege escalation vulnerability in FactoryTalk Activation Manager. Versions V5.02 and below are affected. The vulnerability stems from custom actions within the installer that spawn visible console windows running with SYSTEM privileges during installation or repair operations. An authenticated attacker with Windows credentials could hijack these console windows to obtain a SYSTEM-level command prompt, granting full access to all files, processes, and system resources.

This vulnerability is being addressed with a vendor fix, recommending users update to version V5.03.

The vulnerability is being reported as a privilege escalation vulnerability.

Rockwell Automation recommends users update to software version V5.03 to mitigate the risk.

CISA recommends organizations take defensive measures to minimize the risk of exploitation of these vulnerabilities, including minimizing network exposure for all control system devices and isolating them from business networks. Secure remote access using VPNs, recognizing VPNs may have vulnerabilities and should be updated.

No known public exploitation specifically targeting these vulnerabilities has been reported to CISA at this time.

Read the full article at CISA Advisories