PT-2024-37624 · Rockwell Automation · Pavilion8

Published

2024-07-16

·

Updated

2025-01-31

·

CVE-2024-6435

CVSS v3.1

8.8

High

VectorAV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
Name of the Vulnerable Software and Affected Versions No specific software or versions are mentioned in the provided descriptions.
Description A privilege escalation issue exists in the affected products, allowing a malicious user with basic privileges to access functions that should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data and create users, including creating a user with elevated privileges and reading sensitive information in the "views" section.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Incorrect Permission

Weakness Enumeration

Related Identifiers

CVE-2024-6435

Affected Products

Pavilion8