Rockwell Automation FactoryTalk Activation Manager
Plan PatchCVSS 7.8ICS-CERT ICSA-26-244-04Sep 1, 2026
Rockwell Automation
Attack path
Attack VectorLocal
Auth RequiredLow
ComplexityLow
User InteractionNone needed
Summary
FactoryTalk Activation Manager versions 5.02 and earlier contain an insufficient credential protection vulnerability (CWE-307) that allows local attackers to read stored credentials. This impacts any system using the affected software to manage factory automation access controls. Rockwell Automation recommends updating to version V5.03 or later.
What this means
What could happen
An attacker with local access to a workstation running FactoryTalk Activation Manager could exploit weak credential storage to gain access to factory automation systems and potentially modify or disable production controls.
Who's at risk
This affects any water or electric utility using Rockwell Automation's FactoryTalk suite for engineering workstations or process automation configuration. The risk is highest for sites where engineering workstations run FactoryTalk Activation Manager and are accessible to multiple users or connected to shared networks.
How it could be exploited
An attacker with local user access to a workstation running FactoryTalk Activation Manager v5.02 or earlier can read stored credentials due to insufficient protection mechanisms. These credentials could then be used to access connected industrial control systems or engineering workstations.
Prerequisites
- Local user access to the workstation running FactoryTalk Activation Manager
- FactoryTalk Activation Manager version 5.02 or earlier installed
Low complexityRequires local accessWeak credential storageAffects engineering workstations
Exploitability
Unlikely to be exploited — EPSS score 0.1%
Affected products (2)
2 with fix
ProductAffected VersionsFix Status
FactoryTalk Activation Manager <=V5.02≤ V5.02Fix available
FactoryTalk Activation ManagerAll versionsV5.03
Remediation & Mitigation
0/3
Do now
0/1FactoryTalk Activation Manager
HARDENINGRestrict local user access to workstations running FactoryTalk Activation Manager; limit to authorized engineering and operations staff
Schedule — requires maintenance window
0/1Patching may require device reboot — plan for process interruption
FactoryTalk Activation Manager
HOTFIXUpdate FactoryTalk Activation Manager to version V5.03 or later
Long-term hardening
0/1HARDENINGImplement workstation access controls and monitor for unauthorized local login attempts
CVEs (1)
↑↓ Navigate · Esc Close
API:
/api/v1/advisories/1e3fbd8e-235d-436f-9b1a-a56c8379a1ceGet OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.