CVE-2023-29463

Severity CVSS v4.0:
Pending analysis
Type:
CWE-287 Authentication Issues
Publication date:
12/09/2023
Last modified:
15/09/2023

Description

<br /> The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.<br /> <br />

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:pavilion8:*:*:*:*:*:*:*:* 5.20 (excluding)