PT-2024-6522 · Rockwell Automation · Rockwell Automation Pavilion8
Published
2024-09-11
·
Updated
2024-09-19
·
CVE-2024-7960
CVSS v3.1
9.1
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N |
Name of the Vulnerable Software and Affected Versions:
Rockwell Automation Pavilion8 (affected versions not specified)
Description:
The issue is related to insecure privilege management, allowing a threat actor to view sensitive information and change settings due to an incorrect privilege matrix. This matrix grants users access to functions they should not have. The vulnerability can be exploited remotely.
Recommendations:
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Rockwell Automation Pavilion8