The MachineSense application programmable interface (API) is improperly protected and can be accessed without authentication. A remote attacker could retrieve and modify sensitive information without any authentication.
https://www.cisa.gov/news-events/ics-advisories/icsa-24-025-01