PatchSiren cyber security CVE debrief
CVE-2024-8533 Rockwell Automation CVE debrief
A privilege escalation vulnerability in Rockwell Automation OptixPanel products allows credential exfiltration through improper default file permissions. The vulnerability affects three product lines: 2800C OptixPanel Compact (version 4.0.0.325), 2800S OptixPanel Standard (version 4.0.0.350), and Embedded Edge Compute Module (version 4.0.0.347). The issue was disclosed on September 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Rockwell Automation has released patched versions: 4.0.2.116 for the Compact model, 4.0.2.123 for the Standard model, and 4.0.2.106 for the Embedded Edge Compute Module. The vulnerability requires network access and user interaction, with high attack complexity, but successful exploitation results in complete compromise of confidentiality, integrity, and availability.
- Vendor
- Rockwell Automation
- Product
- 2800C OptixPanel Compact
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2024-09-12
- Original CVE updated
- 2024-09-12
- Advisory published
- 2024-09-12
- Advisory updated
- 2024-09-12
Who should care
Organizations operating Rockwell Automation OptixPanel HMI devices in industrial environments, particularly manufacturing, energy, and critical infrastructure sectors. Security teams responsible for OT/ICS asset management and patch deployment should prioritize this vulnerability due to the credential exfiltration risk and potential for lateral movement in industrial networks.
Technical summary
The vulnerability stems from improper default file permissions on affected Rockwell Automation OptixPanel systems, allowing authenticated or local users to access sensitive credential files. The CVSS 3.1 vector (AV:N/AC:H/PR:N/UI:R/S:U/C:H/I:H/A:H) indicates network accessibility with high attack complexity, no privileges required, and user interaction needed. Successful exploitation enables complete system compromise. The attack surface is reduced by the high complexity requirement and need for user interaction, but the impact is severe given the high-value target environment of industrial control systems.
Defensive priority
HIGH
Recommended defensive actions
- Upgrade affected Rockwell Automation OptixPanel products to patched versions: 2800C OptixPanel Compact to 4.0.2.116, 2800S OptixPanel Standard to 4.0.2.123, or Embedded Edge Compute Module to 4.0.2.106
- Review and harden file permissions on OptixPanel systems to prevent unauthorized credential access
- Implement network segmentation for industrial control systems to limit exposure of OptixPanel devices
- Apply Rockwell Automation's security best practices for industrial automation control systems
- Monitor for anomalous access patterns to credential storage locations on affected systems
Evidence notes
Source: CISA CSAF advisory ICSA-24-256-19. CVSS vector confirms network attack vector with high attack complexity requiring user interaction. Three specific product versions identified with corresponding vendor fixes.
Official resources
-
CVE-2024-8533 CVE record
CVE.org
-
CVE-2024-8533 NVD detail
NVD
-
Source item URL
cisa_csaf
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
-
Source reference
Reference
2024-09-12