Impact
This vulnerability occurs when source code contains hard‑coded URLs that expose JSON data files. The files are reachable without authentication, enabling an attacker to view customer information. The exposure can compromise the confidentiality of data stored in the platform, and the potential impact is limited to information disclosure without affecting integrity or availability.
Affected Systems
The affected product is Rockwell Automation’s DataEdgePlatform DataMosaix Private Cloud, specifically version 7.07. The flaw exists in all installations of this version that deploy the exposed JSON files.
Risk and Exploitability
The CVSS score of 8.7 classifies it as a high‑severity flaw. No EPSS score is available, so the exploitation likelihood cannot be quantified, and it is not yet listed as a known exploited vulnerability. The attack vector is inferred to be unauthenticated network access to the exposed JSON endpoints, which can be performed from any host able to reach the server. Because no authentication is required, the risk is significant for systems exposed to the Internet or to untrusted networks.
OpenCVE Enrichment