First published: Wed Dec 26 2018(Updated: )
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwellautomation Powermonitor 1000 Firmware | =1408-em3a-ent_b | |
Rockwellautomation Powermonitor 1000 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-19616 is a vulnerability discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000.
CVE-2018-19616 allows an unauthenticated user to add, edit, or remove administrators due to a client-side access control issue.
CVE-2018-19616 is considered a high severity vulnerability with a CVSS score of 8.1.
An unauthenticated user can exploit the CVE-2018-19616 vulnerability by bypassing the authentication and manipulating administrators in Rockwell Automation Allen-Bradley PowerMonitor 1000.
At the time of this writing, there is no known fix or patch available for CVE-2018-19616. It is recommended to apply security best practices and monitor for any updates from the vendor or security community.