CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
References
Link | Resource |
---|---|
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html | Vendor Advisory |
Configurations
History
31 Jan 2025, 15:03
Type | Values Removed | Values Added |
---|---|---|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 7.5 |
Summary |
|
|
References | () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - Vendor Advisory | |
First Time |
Rockwellautomation pavilion8
Rockwellautomation |
|
CPE | cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:* |
14 Aug 2024, 20:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2024-08-14 20:15
Updated : 2025-01-31 15:03
NVD link : CVE-2024-40620
Mitre link : CVE-2024-40620
CVE.ORG link : CVE-2024-40620
JSON object : View
Products Affected
rockwellautomation
- pavilion8
CWE
CWE-311
Missing Encryption of Sensitive Data