CVE Database
/

CVE-2024-12371

Back to search

CVE-2024-12371

Published: Dec 18, 2024

Modified: Dec 18, 2024

PUBLISHED

Description

A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.

VendorProductVersions

Rockwell Automation

PM1k 1408-BC3A-485

affected
<4.020

Rockwell Automation

PM1k 1408-BC3A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-TS3A-485

affected
<4.020

Rockwell Automation

PM1k 1408-TS3A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-EM3A-485

affected
<4.020

Rockwell Automation

PM1k 1408-EM3A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-TR1A-485

affected
<4.020

Rockwell Automation

PM1k 1408-TR2A-485

affected
<v4.020

Rockwell Automation

PM1k 1408-EM1A-485

affected
<4.020

Rockwell Automation

PM1k 1408-EM2A-485

affected
<4.020

Rockwell Automation

PM1k 1408-TR1A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-TR2A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-EM1A-ENT

affected
<4.020

Rockwell Automation

PM1k 1408-EM2A-ENT

affected
<4.020

Security Training

Train your team to recognize and prevent security threats with our comprehensive security awareness program.

Start Training

Vulnerability Scanning

Discover vulnerabilities in your applications and infrastructure before attackers do.

Scan Now