← Back to home
ICSA-24-284-17  ·  Published 2024-10-10  ·  View on CISA ICS-CERT ↗

Rockwell Automation Verve Asset Manager

CVSS 6.8 MEDIUM

Risk Summary

Successful exploitation of this vulnerability could allow an unauthorized user to access data they previously had but should no longer have access to.

CVEs (1)

Remediations

  • Rockwell Automation has addressed this issue in version 1.38 and encourages users to update to the newest available version.
  • Rockwell Automation encourages users of the affected software to apply risk mitigations, if possible. Additionally, they encourage users to implement suggested security best practices to minimize the risk of vulnerability:
  • The presence of any mappings will help prevent this vulnerability from being exploited. If all mappings must be removed, manually removing previously mapped users is an effective workaround.
  • Security Best Practices
  • For more information about this issue, please see the advisory on the Rockwell Automation security page.

Affected Vendors

Rockwell Automation

Affected Products (1)

Rockwell Automation · Verve Asset Manager <1.38

Affected Sectors

Chemical, Critical Manufacturing, Water and Wastewater Systems, Healthcare and Public Health, and Energy

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more