FactoryTalk® Activation Manager 中存在一个权限提升的安全问题。该安全问题的根源在于安装程序中的自定义操作在安装或修复过程中会生成以 SYSTEM 权限运行的可见控制台窗口。拥有 Windows 凭据的已认证攻击者可以劫持这些控制台窗口,从而获取具有 SYSTEM 级别的命令提示符,进而实现对所有文件、进程和系统资源的完全访问权限。
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | FactoryTalk® Activation Manager | Version 5.02 and below | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2026-9621 | 9.2 CRITICAL | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9625 | 8.7 HIGH | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9624 | 8.7 HIGH | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9622 | 8.7 HIGH | RSLinx Classic® - Multiple Vulnerabilities |
| CVE-2026-9637 | 8.7 HIGH | CompactLogix® 5380 / ControlLogix® 5580 - Multiple Vulnerabilities |
| CVE-2026-84235 | 8.7 HIGH | Rockwell Automation 1756-ENBT Denial of Service Vulnerability |
| CVE-2026-19472 | 8.7 HIGH | Rockwell Automation ArmorStart® LT Denial Of Service |
| CVE-2025-12768 | 8.6 HIGH | FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability |
| CVE-2026-9634 | 7.0 HIGH | Redundancy Module Configuration Tool - Multiple Vulnerabilities |
| CVE-2026-9633 | 7.0 HIGH | Redundancy Module Configuration Tool - Multiple Vulnerabilities |
| CVE-2026-12663 | 7.0 HIGH | ControlFLASH ® – Improper Access Control |
| CVE-2026-19471 | 6.9 MEDIUM | Rockwell Automation ArmorStart® LT Stored Cross-site scripting |
| CVE-2026-12661 | 4.8 MEDIUM | FactoryTalk® Historian Machine Edition - Out-of-Bounds Write Vulnerability |
No comments yet