CVEs (5)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Pavilion8 Jun 17, 2026 Sep 12, 2024 8.6 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution. |
1Rockwellautomation 1Pavilion8 Jun 17, 2026 Sep 12, 2024 8.8 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that al...Show more |
1Rockwellautomation 1Pavilion8 Jun 17, 2026 Aug 14, 2024 5.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encrypt...Show more |
A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileg...Show more |
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session da...Show more |