Description
A security issue exists within the 5032 16pt Digital Configurable module’s web server. Intercepted session credentials can be used within a 3-minute timeout window, allowing unauthorized users to perform privileged actions.
Problem types
CWE-306: Missing Authentication for Critical Function
Product status
1.011
1.011
1.011
References
www.rockwellautomation.com/...dvisories/advisory.SD1733.html