← Back to home
ICSA-24-226-04  ·  Published 2024-08-13  ·  View on CISA ICS-CERT ↗

Rockwell Automation Pavilion8

CVSS 7.4 HIGH

Risk Summary

Successful exploitation of this vulnerability could allow an attacker to view sensitive data due to a lack of encryption.

CVEs (1)

Remediations

  • Rockwell Automation has released product updates addressing this vulnerability:
  • Pavilion8: update to v6.0 or later
  • Users of the affected software, who are not able to upgrade to one of the corrected versions, are encouraged to apply security best practices, where possible.
  • Interactions between the Console and Dashboard take place on the same machine, the machine should exist behind a firewall and physical access should be limited to authorized personnel.
  • Security Best Practices
  • Customers can use Stakeholder-Specific Vulnerability Categorization to generate more environment-specific prioritization.

Affected Vendors

Rockwell Automation

Affected Products (1)

Rockwell Automation · Pavilion8 >=v5.20

Affected Sectors

Critical Manufacturing

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more