CYBERSECURITYTRACKER
TRACKING6,506 stories in this site build1,309 vulnerability news stories in this site build
Permanent story citation

Rockwell Automation FactoryTalk DataMosaix

This page keeps the story as Cybersecurity Tracker first published it. If the tracker later corrects it, the correction appears below the original and never replaces it.

Back to newsStory 2705

As cited

Copy frozen at (site build).

vulnerabilities

Rockwell Automation FactoryTalk DataMosaix

Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers with high privileges to inject malicious scripts into the Workflows configuration. The vulnerability could enable account takeover, credential theft, or malicious redirection when other users access affected pages. Rockwell Automation recommends upgrading to version 8.03 or later to remediate the issue.

Why it matters: Organizations running DataMosaix Private Cloud 8.02 or earlier in manufacturing and IT environments worldwide should upgrade immediately, as internal attackers with elevated access can compromise other user accounts and systems through script injection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Correction

Correction recorded as of .

vulnerabilities

Rockwell Automation FactoryTalk DataMosaix

Rockwell Automation FactoryTalk DataMosaix Private Cloud versions 8.02 and earlier contain a stored cross-site scripting (XSS) vulnerability that allows authenticated attackers with high privileges to inject malicious scripts into the Workflows configuration. The vulnerability could enable account takeover, credential theft, or malicious redirection when other users access affected pages. Rockwell Automation recommends upgrading to version 8.03 or later to remediate the issue.

Why it matters: Organizations running DataMosaix Private Cloud 8.02 or earlier in manufacturing and IT environments worldwide should upgrade immediately, as internal attackers with elevated access can compromise other user accounts and systems through script injection.

Source published
First seen by Cybersecurity Tracker

Source attribution

Glossary