CVE-2024-6435
Rockwell Automation Privilege Escalation Vulnerability in Pavilion8®
Severity Score
8.7
*CVSS v4
Exploit Likelihood
*EPSS
Affected Versions
*CPE
Public Exploits
0
*Multiple Sources
Exploited in Wild
-
*KEV
Decision
Track
*SSVC
Descriptions
A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious user with basic privileges could perform critical functions such as creating a user with elevated privileges and reading sensitive information in the “views” section.
*Credits:
N/A
CVSS Scores
Attack Vector
Attack Complexity
Attack Requirements
Privileges Required
User Interaction
System
Vulnerable | Subsequent
Confidentiality
Integrity
Availability
* Common Vulnerability Scoring System
SSVC
- Decision:Track
Exploitation
Automatable
Tech. Impact
* Organization's Worst-case Scenario
Timeline
- 2024-07-01 CVE Reserved
- 2024-07-16 CVE Published
- 2024-07-17 EPSS Updated
- 2024-08-01 CVE Updated
- ---------- Exploited in Wild
- ---------- KEV Due Date
- ---------- First Exploit
CWE
- CWE-732: Incorrect Permission Assignment for Critical Resource
CAPEC
- CAPEC-233: Privilege Escalation
References (1)
URL | Tag | Source |
---|---|---|
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1681.html |
URL | Date | SRC |
---|
URL | Date | SRC |
---|
URL | Date | SRC |
---|
Affected Vendors, Products, and Versions
Vendor | Product | Version | Other | Status | ||||||
---|---|---|---|---|---|---|---|---|---|---|
Vendor | Product | Version | Other | Status | <-- --> | Vendor | Product | Version | Other | Status |
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.15.00 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.15.00" | en |
Affected
| ||||||
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.15.01 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.15.01" | en |
Affected
| ||||||
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.16.00 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.16.00" | en |
Affected
| ||||||
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.17.00 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.17.00" | en |
Affected
| ||||||
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.17.01 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.17.01" | en |
Affected
| ||||||
Rockwell Automation Search vendor "Rockwell Automation" | Pavilion8® Search vendor "Rockwell Automation" for product "Pavilion8®" | 5.20.00 Search vendor "Rockwell Automation" for product "Pavilion8®" and version "5.20.00" | en |
Affected
|