CVE-2024-40620

C

VE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.

Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*

History

31 Jan 2025, 15:03

Type Values Removed Values Added
CPE cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Rockwellautomation
Rockwellautomation pavilion8
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - Vendor Advisory

15 Aug 2024, 13:01

Type Values Removed Values Added
New CVE

Information

Published : 2024-08-14 20:15

Updated : 2025-01-31 15:03


NVD link : CVE-2024-40620

Mitre link : CVE-2024-40620

CVE.ORG link : CVE-2024-40620


JSON object : View

Products Affected
CWE
CWE-311

Missing Encryption of Sensitive Data