Rockwell Automation FactoryTalk AssetCentre
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*
- < V15.00.001
A vulnerability exists in all versions of Rockwell Automation FactoryTalk AssetCentre prior to V15.00.001, due to a weak encryption methodology. This encryption vulnerability could allow a threat actor to extract passwords of other users within the application.
Exploitation of this vulnerability could lead to unauthorized access to user accounts by allowing the extraction of passwords from the application's database.
Users are advised to update FactoryTalk AssetCentre to V15.00.01 or later. Additionally, control access to the database to prevent non-essential users from accessing encrypted data.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.