Vulnerability record · CVE-2023-46290 · published 27 October 2023
CVE-2023-46290: Rockwellautomation factorytalk services platform improper authentication vulnerability
Rockwellautomation · Factorytalk Services Platform
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.
Description
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user did not previously log in into the FactoryTalk® Services Platform web service.
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
Affected products
1 vulnerable configurations from NVD's CPE data, grouped by vendor and product.
References
| Link | Tags |
|---|---|
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141165 | Permissions RequiredVendor Advisory |
| https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1141165 | Permissions RequiredVendor Advisory |
Track CVE-2023-46290 inside VULONE
Watch it alongside the ransomware crews, C2 infrastructure and forum chatter that reference it, query it through the API and pull it into your SIEM over TAXII.
Related vulnerabilities
Same products first, then exploited flaws of the same weakness class.
Source: NIST National Vulnerability Database (record CVE-2023-46290), CISA KEV, FIRST EPSS (scores of 2026-09-28). This page is refreshed as NVD updates the record.