PatchSiren

PatchSiren cyber security CVE debrief

CVE-2024-6435 Rockwell Automation CVE debrief

A privilege escalation vulnerability in Rockwell Automation Pavilion 8 allows authenticated users with basic privileges to access administrative functions, potentially enabling unauthorized user creation and sensitive data access.

Vendor
Rockwell Automation
Product
Pavilion 8
CVSS
HIGH 8.8
CISA KEV
Not listed in stored evidence
Original CVE published
2024-07-16
Original CVE updated
2024-07-16
Advisory published
2024-07-16
Advisory updated
2024-07-16

Who should care

Organizations operating Rockwell Automation Pavilion 8 in industrial environments, particularly those in critical infrastructure sectors. Security teams responsible for OT/ICS asset management, identity and access management administrators, and compliance officers monitoring NIST CSF or IEC 62443 adherence should prioritize this vulnerability due to its potential for unauthorized administrative access in process control environments.

Technical summary

CVE-2024-6435 is a privilege escalation vulnerability in Rockwell Automation Pavilion 8 versions 5.15.00 through 5.20.00. The flaw allows authenticated users with basic privileges to access administrative functions that should require elevated privileges. Successful exploitation enables attackers to create users with elevated privileges and read sensitive information from the 'views' section. The vulnerability has a CVSS 3.1 score of 8.8 (HIGH severity) with network attack vector, low attack complexity, and low privilege requirements. Rockwell Automation has released version 6.0 to address this issue. CISA recommends upgrading immediately or applying compensating controls including access restriction and privilege review procedures.

Defensive priority

HIGH

Recommended defensive actions

  • Upgrade to Pavilion8 version 6.0 or greater as recommended by Rockwell Automation
  • If immediate upgrade is not feasible, restrict network access to only essential users
  • Implement periodic review of user access and privileges to confirm accuracy
  • Apply CISA ICS recommended security best practices for defense-in-depth
  • Monitor for unauthorized user creation or privilege modification attempts

Evidence notes

CISA published advisory ICSA-24-198-01 on 2024-07-16, identifying affected versions as Pavilion 8 versions 5.15.00 through 5.20.00. The vulnerability permits basic-privilege users to perform administrative actions including creating elevated-privilege accounts and reading sensitive information in the 'views' section. CVSS 3.1 score of 8.8 reflects network attack vector, low attack complexity, low privileges required, and high impacts to confidentiality, integrity, and availability.

Sources and references

Verified primary and authoritative sources

  • CVE-2024-6435 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2024-6435

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2024-6435 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2024-6435

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2024/icsa-24-198-01.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-24-198-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://us-cert.cisa.gov/sites/default/files/recommended_practices/NCCIC_ICS-CERT_Defense_in_Depth_2016_S508C.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/tips/ICS-TIP-12-146-01B

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.