CVE-2024-40620

CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*

History

31 Jan 2025, 15:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
Summary
  • (es) CVE-2024-40620 IMPACT Existe una vulnerabilidad en el producto afectado debido a la falta de cifrado de información confidencial. La vulnerabilidad provoca que los datos se envíen entre la consola y el panel sin cifrado, lo que se puede ver en los registros de los servidores proxy, lo que podría afectar la confidencialidad de los datos.
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - Vendor Advisory
First Time Rockwellautomation pavilion8
Rockwellautomation
CPE cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*

14 Aug 2024, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 20:15

Updated : 2025-01-31 15:03


NVD link : CVE-2024-40620

Mitre link : CVE-2024-40620

CVE.ORG link : CVE-2024-40620


JSON object : View

Products Affected

rockwellautomation

  • pavilion8
CWE
CWE-311

Missing Encryption of Sensitive Data