PT-2024-9677 · Rockwell Automation · Rockwell Automation Power Monitor 1000
Vera Mens
·
Published
2024-12-16
·
Updated
2025-09-04
·
CVE-2024-12371
CVSS v4.0
9.3
Critical
| Vector | AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation Power Monitor 1000 (affected versions not specified)
Description
A device takeover issue exists, allowing the configuration of a new
Policyholder user without authentication via API. The Policyholder user has the most privileges, enabling edit operations, creation of admin users, and factory resets. This can be exploited by sending a specially crafted API request to create a Policyholder user, potentially giving an attacker full access to the device.Recommendations
At the moment, there is no information about a newer version that contains a fix for this vulnerability.
Missing Authentication
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Rockwell Automation Power Monitor 1000