ZeroHour

CVE-2024-8533

CVSS 4.0
7.7 high
EPSS
1%p68
Published
()
Modified
Description

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

Vendors
rockwellautomation
Products
2800c optixpanel compact firmware, 2800s optixpanel standard firmware, embedded edge compute module firmware
Weakness
CWE-269, CWE-276
Vector
CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

In the news

No ingested article mentions this CVE yet.