PatchSiren cyber security CVE debrief
CVE-2024-37287 Elastic CVE debrief
A remote code execution vulnerability exists in Rockwell Automation Verve Reporting versions prior to 1.39. The vulnerability stems from the product's use of Kibana, which contains a prototype pollution flaw that can be triggered by an attacker with access to machine learning (ML) and alerting features plus write access to internal ML components. Successful exploitation leads to arbitrary code execution within the container boundary. The CVSS 3.1 score of 7.2 (HIGH) reflects network attack vector, low attack complexity, high privileges required, and high impacts to confidentiality, integrity, and availability. CISA published this advisory on November 14, 2024, with an update on November 18, 2024 correcting affected product name and version range. No known exploitation in ransomware campaigns has been reported.
- Vendor
- Elastic
- Product
- Verve Reporting
- CVSS
- HIGH 7.2
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-11-14
- Original CVE updated
- 2024-11-18
- Advisory published
- 2024-11-14
- Advisory updated
- 2024-11-18
Who should care
Organizations operating Rockwell Automation Verve Reporting in industrial control system (ICS) environments, particularly those with enabled machine learning features and multiple administrative users. Critical infrastructure operators in manufacturing, energy, and process industries should prioritize assessment due to potential operational technology (OT) impact.
Technical summary
Verve Reporting incorporates Kibana, which is vulnerable to prototype pollution through its machine learning and alerting features. An authenticated attacker with high privileges (write access to internal ML) can trigger this flaw to achieve arbitrary code execution. The execution context is limited to the container environment. The vulnerability affects versions prior to 1.39. Remediation includes version upgrade, administrative access restriction, role-based access control configuration, and optional ML feature disablement.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade to Verve Reporting version 1.39 or later when available
- Restrict access to the built-in 'verve' administrative account to only those administrators who require it for administrative functions; use separate accounts for day-to-day operations
- Change the password for the built-in 'verve' account if it has been shared
- Assign users the 'all-all' and 'feature-all-all' roles to provide access to most Verve Reporting features without granting permission to execute this vulnerability
- Disable Machine Learning by setting xpack.ml.enabled: false in the Elasticsearch configuration override; contact Verve support for assistance if needed
- Follow CISA ICS recommended practices for defense-in-depth and network segmentation
- Monitor for anomalous activity related to ML and alerting feature access
- resourceLinkAnnotations: [source-item, ref-4, ref-6, ref-10]
Evidence notes
Vulnerability description and affected product version (<1.39) derived from CISA CSAF advisory ICSA-24-319-13. CVSS vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H confirmed in source. Timeline reflects CVE published 2024-11-14 and modified 2024-11-18 per official record.
Sources and references
Verified primary and authoritative sources
-
CVE-2024-37287 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2024-37287
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2024-37287 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37287
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Rockwell Automation Verve Reporting (Update A)
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-13.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-13
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Supplemental source
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Supplemental source
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.