PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-37287 Elastic CVE debrief

A remote code execution vulnerability exists in Rockwell Automation Verve Reporting versions prior to 1.39. The vulnerability stems from the product's use of Kibana, which contains a prototype pollution flaw that can be triggered by an attacker with access to machine learning (ML) and alerting features plus write access to internal ML components. Successful exploitation leads to arbitrary code execution within the container boundary. The CVSS 3.1 score of 7.2 (HIGH) reflects network attack vector, low attack complexity, high privileges required, and high impacts to confidentiality, integrity, and availability. CISA published this advisory on November 14, 2024, with an update on November 18, 2024 correcting affected product name and version range. No known exploitation in ransomware campaigns has been reported.

Vendor
Elastic
Product
Verve Reporting
CVSS
HIGH 7.2
CISA KEV
Not listed in stored evidence
Original CVE published
2024-11-14
Original CVE updated
2024-11-18
Advisory published
2024-11-14
Advisory updated
2024-11-18

Who should care

Organizations operating Rockwell Automation Verve Reporting in industrial control system (ICS) environments, particularly those with enabled machine learning features and multiple administrative users. Critical infrastructure operators in manufacturing, energy, and process industries should prioritize assessment due to potential operational technology (OT) impact.

Technical summary

Verve Reporting incorporates Kibana, which is vulnerable to prototype pollution through its machine learning and alerting features. An authenticated attacker with high privileges (write access to internal ML) can trigger this flaw to achieve arbitrary code execution. The execution context is limited to the container environment. The vulnerability affects versions prior to 1.39. Remediation includes version upgrade, administrative access restriction, role-based access control configuration, and optional ML feature disablement.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to Verve Reporting version 1.39 or later when available
  • Restrict access to the built-in 'verve' administrative account to only those administrators who require it for administrative functions; use separate accounts for day-to-day operations
  • Change the password for the built-in 'verve' account if it has been shared
  • Assign users the 'all-all' and 'feature-all-all' roles to provide access to most Verve Reporting features without granting permission to execute this vulnerability
  • Disable Machine Learning by setting xpack.ml.enabled: false in the Elasticsearch configuration override; contact Verve support for assistance if needed
  • Follow CISA ICS recommended practices for defense-in-depth and network segmentation
  • Monitor for anomalous activity related to ML and alerting feature access
  • resourceLinkAnnotations: [source-item, ref-4, ref-6, ref-10]

Evidence notes

Vulnerability description and affected product version (<1.39) derived from CISA CSAF advisory ICSA-24-319-13. CVSS vector AV:N/AC:L/PR:H/UI:N/S:U/C:H/I:H/A:H confirmed in source. Timeline reflects CVE published 2024-11-14 and modified 2024-11-18 per official record.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-37287 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-37287

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-37287 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-37287

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Rockwell Automation Verve Reporting (Update A)

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-319-13.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-319-13

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Supplemental source

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Supplemental source

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.