Rockwell Automation FactoryTalk Analytics LogixAI Over-Permissive Redis Database Vulnerability
Vulnerability
A database vulnerability has been identified in Rockwell Automation's FactoryTalk Analytics LogixAI, specifically in versions 3.00 and 3.01. The issue arises from an overly permissive Redis database instance, potentially allowing an intranet attacker to access and modify sensitive data.
Impact
Exploitation of this vulnerability could lead to unauthorized access to sensitive data and the ability to alter such data.
Remediation
Users of the affected software versions 3.00 and 3.01 should upgrade to version 3.02 or later. For those unable to upgrade, Rockwell Automation recommends following their security best practices.
Vulnerability Rating
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.
