CVE-2024-12371: Rockwell Automation PowerMonitor™ 1000 Remote Code Execution
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2024-12371?
CVE-2024-12371 is considered a critical vulnerability due to the potential for unauthorized device takeover.
How do I fix CVE-2024-12371?
To fix CVE-2024-12371, ensure that you secure your API access and restrict user privileges until a patch is available from Rockwell Automation.
What devices are impacted by CVE-2024-12371?
CVE-2024-12371 specifically affects the Rockwell Automation Power Monitor 1000.
What kind of access can be gained through CVE-2024-12371?
CVE-2024-12371 allows an attacker to create a new Policyholder user, granting them the highest level of access to the device.
Is it possible to exploit CVE-2024-12371 remotely?
Yes, CVE-2024-12371 can be exploited remotely via an unauthenticated API call.