ZeroHour

CVE-2024-7952

Unauthenticated Data Exposure in Rockwell Automation Product (CVE-2024-7952)

CVSS 4.0
8.7 high
EPSS
<1%p34
Published
()
Modified
AI analysis

Rockwell Automation (the assigned CNA) has disclosed CVE-2024-7952, a data-exposure flaw (CWE-798, use of hard-coded credentials) in one of its products. The affected source code contains hard-coded links pointing to JSON files that can be reached without authentication, so anyone who can reach the affected service over the network can simply request those URLs and retrieve their contents. A successful attacker gains read access to customer data stored in those files; the CVSS 4.0 vector (base score 8.7, high) confirms network reachability with no privileges or user interaction required and high confidentiality impact only, with no integrity or availability impact. The specific affected product and version range are not stated in the available data, so defenders should consult the Rockwell Automation advisory to determine whether they run the affected software. No public proof-of-concept, CISA KEV listing, or confirmed in-the-wild exploitation is known; EPSS currently estimates roughly a 0.4% probability of exploitation in the next 30 days.

What to do: Check Rockwell Automation's security advisory for this CVE to identify the affected product and version, and apply the vendor's patch or update when released, since the hard-coded (CWE-798) nature of the flaw cannot be fixed by configuration changes alone. In the meantime, keep the affected service off the internet or restrict access with firewall rules/ACLs, and block or require authentication for the exposed JSON endpoints. Review web access logs for unauthenticated requests to those files to check whether customer data has already been accessed.

Affected
Rockwell Automation
Estimated exposure
No basis for an estimate.

Order-of-magnitude estimate by the model from install counts, market share and public scan data it knows; verify before quoting.

Description

A data exposure vulnerability exists in the affected product. There are hardcoded links in the source code that lead to JSON files that can be reached without authentication. If exploited, a threat actor could view customer data.

Weakness
CWE-798
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.