CVE-2024-7952

Rockwell Automation · DataEdgePlatform DataMosaix™ Private Cloud

An unauthenticated data exposure vulnerability in Rockwell Automation DataEdgePlatform DataMosaix™ Private Cloud allows attackers to access sensitive customer data via hardcoded JSON file links.

Executive summary

An unauthenticated data exposure vulnerability in Rockwell Automation DataEdgePlatform DataMosaix™ Private Cloud allows unauthorized access to sensitive customer information, posing a high risk.

Vulnerability

This is a data exposure vulnerability caused by hardcoded links in the source code pointing to JSON files. These files are accessible to unauthenticated remote attackers, allowing them to view sensitive customer data.

Business impact

The exploitation of this vulnerability results in the unauthorized disclosure of potentially sensitive customer data, which may lead to significant privacy violations and regulatory non-compliance. Given the CVSS score of 8.7, this flaw represents a high risk to business operations and data integrity, as it does not require any user interaction or authentication to execute.

Remediation

Immediate Action: Review the official Rockwell Automation security advisory (SD1702) and apply all recommended software updates or configuration changes provided by the vendor.

Proactive Monitoring: Inspect web server and application access logs for unusual requests directed toward JSON-formatted files or suspicious endpoint traversal patterns.

Compensating Controls: Implement strict network segmentation and utilize a Web Application Firewall (WAF) to block unauthorized requests to sensitive internal file paths and JSON resources.

Exploitation status

Public Exploit Available: No (exploit_available: false).

Analyst recommendation

The severity of this vulnerability, combined with the lack of required authentication, necessitates immediate attention from security teams. Organizations using the affected versions of the DataEdgePlatform DataMosaix™ Private Cloud should prioritize the application of vendor-supplied patches to prevent unauthorized data access. If a patch is not immediately available, restrict network access to the affected service as a temporary measure.

More Rockwell Automation CVEs

Sources