CVE-2024-12371

CRITICAL

Rockwell Automation Power Monitor 1000 - Privilege Escalation

Title source: llm
STIX 2.1

Description

A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.

Scores

CVSS v4 9.3
EPSS 0.0054
EPSS Percentile 41.0%
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact partial

Details

CWE
CWE-306
Status published
Products (14)
Rockwell Automation/PM1k 1408-BC3A-485 <4.020
Rockwell Automation/PM1k 1408-BC3A-ENT <4.020
Rockwell Automation/PM1k 1408-EM1A-485 <4.020
Rockwell Automation/PM1k 1408-EM1A-ENT <4.020
Rockwell Automation/PM1k 1408-EM2A-485 <4.020
Rockwell Automation/PM1k 1408-EM2A-ENT <4.020
Rockwell Automation/PM1k 1408-EM3A-485 <4.020
Rockwell Automation/PM1k 1408-EM3A-ENT <4.020
Rockwell Automation/PM1k 1408-TR1A-485 <4.020
Rockwell Automation/PM1k 1408-TR1A-ENT <4.020
... and 4 more
Published Dec 18, 2024
Tracked Since Feb 18, 2026