First published: Wed Aug 14 2024(Updated: )
CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
rockwellautomation Pavilion8 | =5.20.00 |
Upgrade to v6.0
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2024-40620 is classified as a critical severity vulnerability due to the lack of encryption for sensitive information.
To fix CVE-2024-40620, upgrade Rockwell Automation Pavilion8 to the latest version that implements proper encryption for data transfers.
CVE-2024-40620 affects Rockwell Automation Pavilion8, specifically version 5.20.00.
CVE-2024-40620 exposes sensitive information that is transmitted unencrypted between the Console and Dashboard.
There are currently no public reports indicating that CVE-2024-40620 is being actively exploited in the wild.