CVE-2018-19616: High severity rockwell automation powermonitor 1000 vulnerability
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2018-19616?
CVE-2018-19616 is a vulnerability discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000.
How does CVE-2018-19616 impact Rockwell Automation Allen-Bradley PowerMonitor 1000?
CVE-2018-19616 allows an unauthenticated user to add, edit, or remove administrators due to a client-side access control issue.
What is the severity of CVE-2018-19616?
CVE-2018-19616 is considered a high severity vulnerability with a CVSS score of 8.1.
How can the CVE-2018-19616 vulnerability be exploited?
An unauthenticated user can exploit the CVE-2018-19616 vulnerability by bypassing the authentication and manipulating administrators in Rockwell Automation Allen-Bradley PowerMonitor 1000.
Is there a fix available for CVE-2018-19616?
At the time of this writing, there is no known fix or patch available for CVE-2018-19616. It is recommended to apply security best practices and monitor for any updates from the vendor or security community.