Back

HIGH

Rockwell Automation OptixPanel™ Privilege Escalation Vulnerability via File Permissions

Published Sep 12, 2024

Description

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

Affected products

Remediation

Vendor solution

Affected Product

First Known in Software Version

Corrected in Software Version

2800C OptixPanel™ Compact

4.0.0.325

4.0.2.116

2800S OptixPanel™ Standard

4.0.0.350

4.0.2.123

Embedded Edge Compute Module

4.0.0.347

4.0.2.106

Mitigations and Workarounds Customers using the affected software are encouraged to apply security best practices

* For information on how to mitigate Security Risks on industrial automation control systems, we encourage customers to implement our suggested security best practices https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1085012/loc/en_US#__highlight  to minimize the risk of the vulnerability.

References (2)

Change history (0)

No recorded changes yet.

Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Sep 12, 2024
Updated Sep 12, 2024
Reserved Sep 6, 2024
CISA Vulnrichment
Updated Sep 12, 2024
NVD
Status Analyzed
Modified Jun 17, 2026
Red Hat
Severity n/a
Public date n/a
ENISA EUVD
Assigner Rockwell
Published Sep 12, 2024
Updated Sep 12, 2024
Exploited since n/a
EUVD-2024-49245