CVE-2024-9412CWE-842

Improper Authorization Vulnerability in Rockwell Automation Verve® Asset Manager

High · published October 8, 2024

CVSS v4.0
8.4
EPSS
0%
Percentile
34.1
In the wild
Unconfirmed
What it is

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.

The record
Technical detail
CVSS v4.0
8.4 · HIGH
Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N
EPSS
0.00408 · 34.1th percentile
Weakness
CWE-842 · Placement of User into Incorrect Group
Published
2024-10-08T19:24Z
EPSS history
Timeline
  • 08 OCT 19:24Z
    Improper Authorization Vulnerability in Rockwell Automation Verve® Asset Manager
    cvelistv5