CVE-2024-6326: Rockwell Automation Unsecured Private Keys in FactoryTalk® System Services
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.
Affected Software
Remediation
Recommended actions to resolve this vulnerability, in priority order.
- Configuration
Set explicit (restrictive) permissions on the backup folder so sensitive interim copies (private keys, passwords, pre-shared keys, database folders) are not temporarily exposed during back-up or restore operations.
Rockwell Automation FactoryTalk® System Service (backup folder) explicit permissions on the backup folder = Restrict access so that only authorized users/processes can read/write the backup/interim folder contents - Operational
Invalidate (revoke) any existing vulnerable private keys/digital certificates obtained through the interim backup/restore exposure and regenerate new secure ones for Rockwell Automation FactoryTalk® System Service.
Event History
Frequently Asked Questions
What is the severity of CVE-2024-6326?
CVE-2024-6326 is considered a high severity vulnerability due to the potential exposure of sensitive information.
How do I fix CVE-2024-6326?
To fix CVE-2024-6326, upgrade the affected software to a patched version provided by Rockwell Automation.
What types of sensitive information are exposed by CVE-2024-6326?
CVE-2024-6326 can expose private keys, passwords, pre-shared keys, and database information.
Which versions of Rockwell Automation software are affected by CVE-2024-6326?
CVE-2024-6326 affects FactoryTalk® System Services and FactoryTalk® Policy Manager version 6.40.0.
Who can exploit CVE-2024-6326?
A malicious user with access to initiate a back-up or restore process can exploit CVE-2024-6326.