CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
Metrics
Affected Vendors & Products
References
History
Fri, 31 Jan 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
First Time appeared |
Rockwellautomation
Rockwellautomation pavilion8 |
|
CPEs | cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:* | |
Vendors & Products |
Rockwellautomation
Rockwellautomation pavilion8 |
|
Metrics |
cvssV3_1
|
Wed, 14 Aug 2024 21:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Wed, 14 Aug 2024 20:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality. | |
Title | Rockwell Automation Pavilion8® Unencrypted Data Vulnerability via HTTP protocol | |
Weaknesses | CWE-311 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-08-14T20:30:57.375Z
Reserved: 2024-07-08T14:58:18.172Z
Link: CVE-2024-40620

Updated: 2024-08-14T20:30:54.268Z

Status : Analyzed
Published: 2024-08-14T20:15:12.410
Modified: 2025-01-31T15:03:56.407
Link: CVE-2024-40620

No data.