PT-2024-8121 · Rockwell Automation · Verve Asset Manager+1

Published

2024-10-04

·

Updated

2024-10-10

·

CVE-2024-9412

CVSS v2.0

9.0

High

VectorAV:N/AC:L/Au:S/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions: Rockwell Automation products (affected versions not specified) Verve Asset Manager versions prior to v1.38
Description: An improper authorization issue exists in the affected products, potentially allowing an unauthorized user to sign in and access data they should no longer have access to. This could occur due to unexpected or accidental removal of role mappings by the administrator. The vulnerability may also enable an attacker to manipulate user groups, potentially leading to unauthorized access.
Recommendations: For Verve Asset Manager versions prior to v1.38, upgrade to version v1.38 or later. For other affected Rockwell Automation products, at the moment, there is no information about a newer version that contains a fix for this vulnerability.

Weakness Enumeration

Related Identifiers

BDU:2024-09653
CVE-2024-9412

Affected Products

Rockwell Automation Products
Verve Asset Manager