CVE-2024-12371
Published: Dec 18, 2024
Modified: Dec 18, 2024
Description
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.
| Vendor | Product | Versions |
|---|---|---|
Rockwell Automation | PM1k 1408-BC3A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-BC3A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-TS3A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-TS3A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-EM3A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-EM3A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-TR1A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-TR2A-485 | affected <v4.020 |
Rockwell Automation | PM1k 1408-EM1A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-EM2A-485 | affected <4.020 |
Rockwell Automation | PM1k 1408-TR1A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-TR2A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-EM1A-ENT | affected <4.020 |
Rockwell Automation | PM1k 1408-EM2A-ENT | affected <4.020 |
Security Training
Train your team to recognize and prevent security threats with our comprehensive security awareness program.
Start TrainingVulnerability Scanning
Discover vulnerabilities in your applications and infrastructure before attackers do.
Scan Now