PT-2024-6522 · Rockwell Automation · Rockwell Automation Pavilion8

Published

2024-09-11

·

Updated

2024-09-19

·

CVE-2024-7960

CVSS v3.1

9.1

Critical

VectorAV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N
Name of the Vulnerable Software and Affected Versions: Rockwell Automation Pavilion8 (affected versions not specified)
Description: The issue is related to insecure privilege management, allowing a threat actor to view sensitive information and change settings due to an incorrect privilege matrix. This matrix grants users access to functions they should not have. The vulnerability can be exploited remotely.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Weakness Enumeration

Related Identifiers

BDU:2024-07664
CVE-2024-7960

Affected Products

Rockwell Automation Pavilion8