Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

github логотип

GHSA-86cp-4p5x-5mrm

Опубликовано: 08 окт. 2024
Источник: github
Github: Не прошло ревью
CVSS4: 8.4

Описание

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.

EPSS

Процентиль: 28%
0.00102
Низкий

8.4 High

CVSS4

Дефекты

CWE-842

Связанные уязвимости

nvd
больше 1 года назад

An improper authorization vulnerability exists in the Rockwell Automation affected products that could allow an unauthorized user to sign in. While removal of all role mappings is unlikely, it could occur in the case of unexpected or accidental removal by the administrator. If exploited, an unauthorized user could access data they previously but should no longer have access to.

CVSS3: 6.8
fstec
больше 1 года назад

Уязвимость программного средства автоматизации и учета Asset Manager, связанная с занесением пользователя в несоответствующую группу, позволяющая повысить свои привилегии

EPSS

Процентиль: 28%
0.00102
Низкий

8.4 High

CVSS4

Дефекты

CWE-842