Show filters
273 Total Results
Displaying 11-20 of 273
Sort by:
Attacker Value
Unknown
CVE-2024-8533
Disclosure Date: September 12, 2024 (last updated September 19, 2024)
A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
0
Attacker Value
Unknown
CVE-2024-6077
Disclosure Date: September 12, 2024 (last updated September 20, 2024)
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.
0
Attacker Value
Unknown
CVE-2024-45826
Disclosure Date: September 12, 2024 (last updated October 03, 2024)
CVE-2024-45826 IMPACT
Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If exploited, a user can install an executable file.
0
Attacker Value
Unknown
CVE-2024-45825
Disclosure Date: September 12, 2024 (last updated October 03, 2024)
CVE-2024-45825 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
0
Attacker Value
Unknown
CVE-2024-45823
Disclosure Date: September 12, 2024 (last updated October 03, 2024)
CVE-2024-45823 IMPACT
An
authentication bypass vulnerability exists in the affected product. The
vulnerability exists due to shared secrets across accounts and could allow a threat
actor to impersonate a user if the threat actor is able to enumerate additional
information required during authentication.
0
Attacker Value
Unknown
CVE-2024-45824
Disclosure Date: September 12, 2024 (last updated February 01, 2025)
CVE-2024-45824 IMPACT
A remote
code vulnerability exists in the affected products. The vulnerability occurs
when chained with Path Traversal, Command Injection, and XSS Vulnerabilities
and allows for full unauthenticated remote code execution. The link in the
mitigations section below contains patches to fix this issue.
0
Attacker Value
Unknown
CVE-2024-7513
Disclosure Date: August 14, 2024 (last updated February 01, 2025)
CVE-2024-7513 IMPACT
A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permissions allowing any user to edit or replace files, which are executed by account with elevated permissions.
0
Attacker Value
Unknown
CVE-2024-40620
Disclosure Date: August 14, 2024 (last updated February 01, 2025)
CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
0
Attacker Value
Unknown
CVE-2024-40619
Disclosure Date: August 14, 2024 (last updated February 01, 2025)
CVE-2024-40619 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable fault causing a denial-of-service.
0
Attacker Value
Unknown
CVE-2024-6326
Disclosure Date: July 16, 2024 (last updated September 24, 2024)
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are temporarily copied to an interim folder. This vulnerability is due to the lack of explicit permissions set on the backup folder. If private keys are obtained by a malicious user, they could impersonate resources on the secured network.
0