CVE-2024-40620

CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encryption, which can be seen in the logs of proxy servers, potentially impacting the data's confidentiality.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*

History

31 Jan 2025, 15:03

Type Values Removed Values Added
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
CPE cpe:2.3:a:rockwellautomation:pavilion8:5.20.00:*:*:*:*:*:*:*
First Time Rockwellautomation
Rockwellautomation pavilion8
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD%201691.html - Vendor Advisory

Information

Published : 2024-08-14 20:15

Updated : 2025-01-31 15:03


NVD link : CVE-2024-40620

Mitre link : CVE-2024-40620

CVE.ORG link : CVE-2024-40620


JSON object : View

Products Affected

rockwellautomation

  • pavilion8
CWE
CWE-311

Missing Encryption of Sensitive Data