CVE-2016-4531 is a critical vulnerability affecting Rockwell Automation FactoryTalk EnergyMetrix versions prior to 2.20.00, where the system fails to invalidate user credentials upon logout. This flaw allows remote attackers to gain unauthorized access to an unattended workstation, potentially leading to low impact on confidentiality, integrity, and availability. With a CVSS score of 7.3 (HIGH) and an EPSS score indicating higher than 95% of all CVEs, it presents a significant risk despite no known active exploits or publicly available exploit code. Community discussion and media coverage suggest moderate awareness of this vulnerability.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
<= 2.10.00CPE matchmatch criteria | cpe:2.3:a:rockwellautomation:factorytalk_energrymetrix:*:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:L/I:L/A:L
The average CVE in this peer group has 0.0 Twitter, 0.0 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.4 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.