Vulnerability Details CVE-2023-2444
A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product. Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 28.7%
CVSS Severity
CVSS v3 Score 7.1
Products affected by CVE-2023-2444
-
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:8.0
-
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:8.10
-
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:8.20
-
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:8.30
-
cpe:2.3:a:rockwellautomation:factorytalk_vantagepoint:8.31