Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2024-6435


A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious user with basic privileges could perform critical functions such as creating a user with elevated privileges and reading sensitive information in the “views” section.


Published

2024-07-16T13:15:13.630

Last Modified

2025-01-31T15:01:23.807

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 8.8 (HIGH)

Weaknesses
  • Type: Secondary
    CWE-732
  • Type: Primary
    CWE-732

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation pavilion8 5.15.00 Yes
Application rockwellautomation pavilion8 5.15.01 Yes
Application rockwellautomation pavilion8 5.16.00 Yes
Application rockwellautomation pavilion8 5.17.00 Yes
Application rockwellautomation pavilion8 5.17.01 Yes
Application rockwellautomation pavilion8 5.20.00 Yes

References