Executive Summary

Industrial automation leader Rockwell Automation, in coordination with the Cybersecurity and Infrastructure Security Agency (CISA), has issued a critical cybersecurity advisory warning of a severe authentication bypass vulnerability in FactoryTalk View Site Edition (SE). Designated CVE-2026-60891, the flaw carries a CVSS v3.1 base score of 9.8 (Critical) and affects enterprise supervisory human-machine interface (HMI) deployments worldwide.

FactoryTalk View SE is utilized across high-consequence industries, including municipal water distribution, pharmaceutical manufacturing, food processing, and chemical refining. Successful exploitation enables an unauthenticated attacker connected to the supervisory industrial network to bypass client authentication and launch operator displays with full engineering and administrative privileges.

Root Cause Analysis: Insecure Client Session Negotiation

Communication between FactoryTalk View SE Client workstations and the FactoryTalk Directory server occurs over proprietary TCP RPC channels (specifically TCP port 4242 and port 443). When an operator logs in, the FactoryTalk Security subsystem generates a digital security descriptor token representing user permissions and group memberships.

Security analysis identified that the client initialization routine accepted pre-constructed security descriptor objects without verifying cryptographic digital signatures against the central FactoryTalk Directory. An attacker operating a customized RPC client can forge a session descriptor asserting membership in the FactoryTalk Administrators group, prompting the client application to grant full access to supervisory displays, setpoint controls, and alarm acknowledgments.

Session Compromise Sequence:
1. Attacker connects to FactoryTalk View SE Server on TCP Port 4242
2. Attacker transmits crafted ClientInit RPC packet with forged SecurityDescriptor
3. Server validates structure but omits cryptographic signature verification
4. Server returns valid active SessionToken with Administrator role
5. Attacker launches HMI display with full rights to modify plant setpoints

Operational Impact on Critical Infrastructure Operations

In accordance with IEC 62443 safety and security requirements, supervisory HMI consoles at Level 2/3 must maintain strict access control. The unauthorized compromise of FactoryTalk View SE allows adversaries to:

  • Manipulate chemical dosing and valve pressure setpoints on operational water treatment consoles.
  • Mute and acknowledge safety alarms, blinding operators to dangerous industrial hardware conditions.
  • Extract proprietary manufacturing recipes and batch execution histories from central SCADA databases.

Remediation Playbook

Rockwell Automation has released software patch rollups and advises all plant operators to execute the following mitigation sequence immediately:

  1. Apply Software Patches: Install FactoryTalk View SE v14.00.01 or apply hotfix rollup CPR9 SR14 to v12.00 and v13.00 installations.
  2. Enable FactoryTalk Security Strict Mode: Configure FactoryTalk Directory to enforce strict cryptographic signature validation and reject legacy unauthenticated client connections.
  3. Isolate Level 3 Supervisory Networks: Prohibit all routing between enterprise IT subnets and the FactoryTalk HMI network, placing all client workstations in dedicated industrial DMZs.