// For flags

CVE-2024-8533

Rockwell Automation OptixPanel™ Privilege Escalation Vulnerability via File Permissions

Severity Score

7.7
*CVSS v4

Exploit Likelihood

*EPSS

Affected Versions

*CPE

Public Exploits

0
*Multiple Sources

Exploited in Wild

-
*KEV

Decision

Track*
*SSVC
Descriptions

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

*Credits: N/A
CVSS Scores
Attack Vector
Network
Attack Complexity
High
Attack Requirements
None
Privileges Required
None
User Interaction
Passive
System
Vulnerable | Subsequent
Confidentiality
High
None
Integrity
High
None
Availability
High
None
* Common Vulnerability Scoring System
SSVC
  • Decision:Track*
Exploitation
None
Automatable
No
Tech. Impact
Total
* Organization's Worst-case Scenario
Timeline
  • 2024-09-06 CVE Reserved
  • 2024-09-12 CVE Published
  • 2024-09-12 CVE Updated
  • 2024-09-19 EPSS Updated
  • ---------- Exploited in Wild
  • ---------- KEV Due Date
  • ---------- First Exploit
CWE
  • CWE-269: Improper Privilege Management
CAPEC
  • CAPEC-122: Privilege Abuse
Affected Vendors, Products, and Versions
Vendor Product Version Other Status
Vendor Product Version Other Status <-- --> Vendor Product Version Other Status
Rockwell Automation
Search vendor "Rockwell Automation"
2800C OptixPanel™ Compact
Search vendor "Rockwell Automation" for product "2800C OptixPanel™ Compact"
4.0.0.325
Search vendor "Rockwell Automation" for product "2800C OptixPanel™ Compact" and version "4.0.0.325"
en
Affected
Rockwell Automation
Search vendor "Rockwell Automation"
2800S OptixPanel™ Standard
Search vendor "Rockwell Automation" for product "2800S OptixPanel™ Standard"
4.0.0.350
Search vendor "Rockwell Automation" for product "2800S OptixPanel™ Standard" and version "4.0.0.350"
en
Affected
Rockwell Automation
Search vendor "Rockwell Automation"
Embedded Edge Compute Module
Search vendor "Rockwell Automation" for product "Embedded Edge Compute Module"
4.0.0.347
Search vendor "Rockwell Automation" for product "Embedded Edge Compute Module" and version "4.0.0.347"
en
Affected