CVE-2024-21915: Rockwell Automation FactoryTalk® Service Platform Elevated Privileges Vulnerability Through Web Service Functionality
A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive data, delete data and render the FTSP system unavailable.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Upgrade
Upgrade
Rockwell Automation FactoryTalk® Service Platform (FTSP)to a version that resolves this vulnerability.Fixed in 2.74 or later - Compensating control
Implement Rockwell Automation’s suggested security best practices mentioned in “Security Best Practices” (a_id/1085012) to minimize the risk of the FactoryTalk® Service Platform elevated privileges vulnerability through web service functionality.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-21915?
CVE-2024-21915 is a privilege escalation vulnerability rated as high severity.
How do I fix CVE-2024-21915?
To fix CVE-2024-21915, update the Rockwell Automation FactoryTalk Services Platform to a version greater than 2.74.
What systems are affected by CVE-2024-21915?
CVE-2024-21915 affects Rockwell Automation FactoryTalk Services Platform versions up to 2.74.
What can an attacker do with CVE-2024-21915?
An attacker exploiting CVE-2024-21915 can escalate their privileges to that of an FTSP Administrator Group.
How can I determine if my system is vulnerable to CVE-2024-21915?
To determine if your system is vulnerable to CVE-2024-21915, verify if you are using a vulnerable version of Rockwell Automation FactoryTalk Services Platform.