Security
Headlines
HeadlinesLatestCVEs

Headline

CVE-2023-2444: Cross Site Request Forgery in FactoryTalk® Vantagepoint®

A cross site request forgery vulnerability exists in Rockwell Automation’s FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could impersonate the legitimate user and send requests to the affected product. Additionally, if an attacker sends an untrusted link to a computer that is not on the same domain as the server and a user opens the FactoryTalk Vantagepoint website, enters credentials for the FactoryTalk Vantagepoint server, and clicks on the malicious link a cross site request forgery attack would be successful as well.

CVE
#vulnerability#web#microsoft#git

Skip Navigation

menu

  • Support Center
  • Get Support Chat & Submit a Question Phone Support Holiday Schedule
  • Training & Webinars
  • Online Forum
  • Customer Care Customer Care Overview Phone Support Holiday Schedule

Sign In

Quickly log in or create an account using an existing service

Yahoo

What will happen: When you click on this button you will be taken to Yahoo. Once you log in, Yahoo will verify you and send you back here where you’ll be logged in!

Log In or Create an AccountOpens new dialog

Please log in to continue, Username Password

Email Address *

Username *

Password

Re-enter a value for the field ‘Password’

Must match Password

First Name *

Last Name *

Forgot your username or password?

The page will refresh upon submission. Any pending input will be lost.

03-Feb-2022 - Important product notice regarding Microsoft vulnerability patch (MS KB5004442)

Current product hierarchy

  1. Information Software
  2. Production Management
  3. FactoryTalk VantagePoint

ID: PN1626 | Access Levels: Everyone

Search

Did you mean:

Published DatePublished Date 05/11/2023

Login Required to View Full Answer Content

Please use the ‘Sign In’ button above

CVE: Latest News

CVE-2023-50976: Transactions API Authorization by oleiman · Pull Request #14969 · redpanda-data/redpanda