CVE-2024-10943: Rockwell Automation Factorytalk Updater
Critical severity, CVSS 9.1. EPSS: 0.5% chance of exploitation in the next 30 days.
An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a threat actor to impersonate a user if the threat actor is able to enumerate additional information required during authentication.
Affected products
- Rockwell Automation Factorytalk Updater: version V4.00.00-4.10.00 only
- Rockwellautomation Factorytalk Updater: from 4.00.00, up to and including 4.20.00
Published 2024-11-12. Last modified 2026-06-17.