CVE-2024-8533

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.
ProviderTypeBase ScoreAtk. VectorAtk. ComplexityPriv. RequiredVector
NISTNIST
8.8 HIGH
NETWORK
LOW
LOW
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H
RockwellCNA
---
---
CISA-ADPADP
---
---
Base Score
CVSS 3.x
EPSS Score
Percentile: 15%
VendorProductVersion
rockwellautomation2800c_optixpanel_compact_firmware
4.0.0.325 ≤
𝑥
< 4.0.2.116
rockwellautomation2800s_optixpanel_standard_firmware
4.0.0.350 ≤
𝑥
< 4.0.2.123
rockwellautomationembedded_edge_compute_module_firmware
4.0.0.347 ≤
𝑥
< 4.0.2.106
𝑥
= Vulnerable software versions