Improper privilege management in Rockwell Automation products - CVE-2024-8533
Published: September 13, 2024
Vulnerability identifier: #VU97246
CSH Severity: Medium
CVSS v4: 7.5 [CVSS:4.0/AV:N/AC:L/AT:P/PR:N/UI:A/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N]
CVE-ID: CVE-2024-8533
CWE-ID: CWE-269
Exploitation vector: Remote access
Exploit availability:
No public exploit available
Vulnerability details
The vulnerability allows a remote attacker to escalate privileges.
The vulnerability exists due to improper default file permissions. A remote attacker can exfiltrate credentials and escalate privileges.
Affected software
2800C OptixPanel Compact
Embedded Edge Compute Module
2800S OptixPanel Standard
Embedded Edge Compute Module
2800S OptixPanel Standard
How to mitigate CVE-2024-8533
Install updates from vendor's website.
2800C OptixPanel Compact - update to 4.0.2.116
Embedded Edge Compute Module - update to 4.0.2.106
2800S OptixPanel Standard - update to 4.0.2.123
Embedded Edge Compute Module - update to 4.0.2.106
2800S OptixPanel Standard - update to 4.0.2.123