Data Exposure Vulnerability in Rockwell Automation Product
CVE-2024-7952

8.7HIGH

What is CVE-2024-7952?

A data exposure vulnerability has been identified in Rockwell Automation products, wherein hardcoded links in the source code allow unauthorized access to JSON files. These files can be accessed without any authentication, posing a risk to customer data integrity and confidentiality. If exploited, malicious actors can potentially view sensitive customer information, raising serious cybersecurity concerns.

Affected Version(s)

DataEdgePlatform DataMosaix™ Private Cloud <=7.07

References

CVSS V4

Score:
8.7
Severity:
HIGH
Confidentiality:
High
Integrity:
None
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.