Description
A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.
Problem types
CWE-286: Incorrect User Management
Product status
All prior to 6.50
References
www.rockwellautomation.com/...dvisories/advisory.SD1735.html