Lucene search

K
cveRockwellCVE-2023-29463
HistorySep 12, 2023 - 5:15 p.m.

CVE-2023-29463

2023-09-1217:15:09
CWE-287
Rockwell
web.nvd.nist.gov
16
cve-2023-29463
jmx console
rockwell automation pavilion8
unauthenticated access
session data
forced logouts
nvd

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

18.3%

The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.

Affected configurations

Nvd
Node
rockwellautomationpavilion8Range<5.20
VendorProductVersionCPE
rockwellautomationpavilion8*cpe:2.3:a:rockwellautomation:pavilion8:*:*:*:*:*:*:*:*

CNA Affected

[
  {
    "defaultStatus": "unaffected",
    "product": "Pavilion8",
    "vendor": "Rockwell Automation",
    "versions": [
      {
        "status": "affected",
        "version": "<5.20"
      }
    ]
  }
]

CVSS3

8.8

Attack Vector

NETWORK

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

AI Score

5.4

Confidence

High

EPSS

0.001

Percentile

18.3%

Related for CVE-2023-29463