216.73.217.22

CVE-2024-7960

· Published 12/09/2024 21:15 · Modified 19/09/2024 01:52

Labels: CVE-2024-7960 2024-09-12CVE-2024-7960CWE-269NVD-CWE-noinfo[email protected]

Essential information

Published
12/09/2024 21:15
Modified
19/09/2024 01:52
Author
Creator
CVSS
9.1 CRITICAL (v3.1)
CISA KEV
No
CWE
CVSS vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

CVSS metrics

Description

The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.

NVD status

Status
Analyzed — CVE has had analysis completed and all data associations made.
Source
[email protected]
NVD
View on NVD

Affected products (CPE)

ProductCPE
rockwellautomation / pavilion8 cpe:2.3:a:rockwellautomation:pavilion8:*:*:*:*:*:*:*:*

References