PT-2024-6591 · Rockwell Automation · Embedded Edge Compute Module+2

Published

2024-09-12

·

Updated

2024-09-19

·

CVE-2024-8533

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Rockwell Automation products (affected versions not specified)
Description: A privilege escalation issue exists due to improper default file permissions, allowing users to exfiltrate credentials and escalate privileges. This can be exploited by a remote attacker to gain user credentials and increase their privileges. The issue affects the management of graphical user interface software on industrial devices, including the Rockwell Automation 2800C OptixPanel Compact, 2800S OptixPanel Standard, and the Embedded Edge Compute Module.
Recommendations: At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Improper Privilege Management

Incorrect Default Permissions

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2024-07737
CVE-2024-8533

Affected Products

Embedded Edge Compute Module
Rockwell Automation 2800C Optixpanel Compact
Rockwell Automation 2800S Optixpanel Standard