The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.
History

Thu, 19 Sep 2024 02:15:00 +0000

Type Values Removed Values Added
Weaknesses NVD-CWE-noinfo
CPEs cpe:2.3:a:rockwellautomation:pavilion8:*:*:*:*:*:*:*:*
Metrics cvssV3_1

{'score': 9.1, 'vector': 'CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N'}


Thu, 12 Sep 2024 21:30:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation pavilion8
CPEs cpe:2.3:a:rockwellautomation:pavilion8:-:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation
Rockwellautomation pavilion8
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Thu, 12 Sep 2024 20:30:00 +0000

Type Values Removed Values Added
Description The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.
Title Rockwell Automation Incorrect Privileges and Path Traversal Vulnerability in Pavilion8®
Weaknesses CWE-269
References
Metrics cvssV4_0

{'score': 8.8, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:L/VA:L/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2024-09-12T20:15:09.946Z

Updated: 2024-09-12T20:49:51.544Z

Reserved: 2024-08-19T18:56:36.513Z

Link: CVE-2024-7960

cve-icon Vulnrichment

Updated: 2024-09-12T20:49:45.879Z

cve-icon NVD

Status : Analyzed

Published: 2024-09-12T21:15:03.153

Modified: 2024-09-19T01:52:55.193

Link: CVE-2024-7960

cve-icon Redhat

No data.