Rockwell FactoryTalk Services Platform 6.60 Authentication Bypass (SD1786)

high Nessus Plugin ID 329329

Synopsis

An application installed on the remote Windows host is affected by an authentication bypass vulnerability.

Description

The version of Rockwell FactoryTalk Services Platform installed on the remote Windows host is 6.60. It is, therefore, affected by an authentication bypass vulnerability:

- A vulnerability exists that allows an attacker to bypass JWT signature validation during Okta Web Authentication.
The application does not verify that the JWT algorithm is configured for RSA, enabling an attacker to set the algorithm to 'none' and craft forged tokens. This could allow an authenticated low-privilege user to impersonate any authorized user on the FTSP server, resulting in unauthorized access to system configuration and the ability to grant permissions to other systems protected by FTSP. (CVE-2026-10714)

Note that Nessus has not tested for this issue but has instead relied only on the application's self-reported version number. The fix for this vulnerability is a patch applied to an existing version, which Nessus is unable to detect.

Solution

Apply patch RAID 1158263 or refer to vendor advisory SD1786.

See Also

http://www.nessus.org/u?4fcac294

Plugin Details

Severity: High

ID: 329329

File Name: rockwell_factorytalk_services_platform_sd_1786.nasl

Version: 1.1

Type: Local

Family: SCADA

Published: 7/24/2026

Updated: 7/24/2026

Supported Sensors: Nessus

Risk Information

VPR

Risk Factor: Medium

Score: 4.3

Percentile: 53.63

CVSS v2

Risk Factor: Medium

Base Score: 6

Vector: CVSS2#AV:L/AC:H/Au:S/C:C/I:C/A:C

CVSS Score Source: CVE-2026-10714

CVSS v3

Risk Factor: High

Base Score: 7.8

Vector: CVSS:3.0/AV:L/AC:H/PR:L/UI:N/S:C/C:H/I:H/A:H

CVSS v4

Risk Factor: High

Base Score: 8.8

Vector: CVSS:4.0/AV:L/AC:H/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H

Vulnerability Information

CPE: cpe:/a:rockwellautomation:factorytalk_services_platform

Required KB Items: SMB/Registry/Enumerated, installed_sw/Rockwell FactoryTalk Services Platform

Patch Publication Date: 7/14/2026

Vulnerability Publication Date: 7/14/2026

Reference Information

CVE: CVE-2026-10714

IAVA: 2026-B-0200