Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
Rewterz penetration testing services help organizations determine if a cyber attacker can gain access to their critical assets while giving them detailed insights of the overall business impact of a cyber attack.
Before Rewterz got its start, the market was in dire need of a specialized and dedicated information security company. It was nearly impossible for businesses to find a trustworthy provider that could truly cover all of their bases. We wanted to meet this need, giving companies across the globe a chance to get ahead while knowing that their data is in good hands.
High
CVE-2023-2639 CVSS:4.1
Rockwell Automation FactoryTalk Services Platform could allow a remote authenticated attacker to obtain sensitive information, caused by origin validation errors. By persuading a victim to visit a specially crafted Web site, an attacker could exploit this vulnerability to obtain sensitive information.
CVE-2023-2638 CVSS:5.9
Rockwell Automation FactoryTalk Services Platform could allow a local authenticated attacker to bypass security restrictions, caused by improper authorization in FTSSBackupRestore.exe. By using a malicious backup archive. an attacker could exploit this vulnerability to cause the loading of malicious configuration archives.
CVE-2023-2637 CVSS:7.3
Rockwell Automation FactoryTalk Services Platform contains default hardcoded cryptographic key. A local authenticated attacker could exploit this vulnerability to generate administrator cookies.
CVE-2023-2778 CVSS:7.5
Rockwell Automation FactoryTalk Transaction Manager is vulnerable to a denial of service, caused by uncontrolled resource consumption flaw. By sending a modified packet to port 400, a remote attacker could exploit this vulnerability to cause a crash or experience a high CPU or memory usage condition.
Rockwell Automation
Refer to Rockwell Automation Web site for patch, upgrade or suggested workaround information.