Description
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.
Problem types
CWE-200 Exposure of Sensitive Information to an Unauthorized Actor
Product status
Version 1.0.0 or below
References
www.rockwellautomation.com/...dvisories/advisory.SD1740.html