CVE-2024-8533

HIGH

Rockwell Automation - Privilege Escalation

Title source: llm
STIX 2.1

Description

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

Scores

CVSS v3 8.8
EPSS 0.0009
EPSS Percentile 25.7%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-269 CWE-276
Status published
Products (3)
rockwellautomation/2800c_optixpanel_compact_firmware 4.0.0.325 - 4.0.2.116
rockwellautomation/2800s_optixpanel_standard_firmware 4.0.0.350 - 4.0.2.123
rockwellautomation/embedded_edge_compute_module_firmware 4.0.0.347 - 4.0.2.106
Published Sep 12, 2024
Tracked Since Feb 18, 2026