Unauthorized Access in Rockwell Automation Products
CVE-2024-7956

7.6HIGH

What is CVE-2024-7956?

A flaw in Rockwell Automation software products enables unauthorized access to user projects. Threat actors with basic user privileges can exploit this vulnerability. Once exploited, they may gain the capability to modify or delete existing projects, posing a significant risk to data integrity and user trust. Organizations should assess their use of affected versions and implement appropriate security measures to prevent exploitation.

Affected Version(s)

DataMosaix™ Private Cloud <=7.07

References

CVSS V4

Score:
7.6
Severity:
HIGH
Confidentiality:
High
Integrity:
High
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
Physical
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.