CVE-2024-7953

8.7

Rockwell Automation · DataEdgePlatform DataMosaix Private Cloud

A vulnerability in Rockwell Automation DataEdgePlatform DataMosaix Private Cloud allows an authenticated user to escalate privileges to project administrator.

Executive summary

A high-severity privilege escalation vulnerability in Rockwell Automation DataEdgePlatform DataMosaix Private Cloud enables authenticated users to gain unauthorized administrative control over projects.

Vulnerability

The flaw allows any authenticated user to create a project and assume the role of administrator for that specific project. This improper authorization logic permits users to perform unauthorized project modifications, including the deletion of data.

Business impact

The ability for a standard user to gain administrative control over project resources poses a significant risk to data integrity and operational continuity. Given the CVSS score of 8.7, this vulnerability facilitates unauthorized project management actions that could lead to the loss of project assets or configuration tampering, potentially disrupting critical industrial workflows.

Remediation

Immediate Action: Review the Rockwell Automation security advisory SD1702 and apply all recommended security updates or configuration changes provided by the vendor.

Proactive Monitoring: Audit user activity logs specifically for project creation events and administrative privilege assignments to identify suspicious account behavior.

Compensating Controls: Implement strict identity and access management policies to limit the number of users capable of creating projects until a patch is applied.

Exploitation status

Public Exploit Available: No (exploit_available: false)

Analyst recommendation

Organizations utilizing affected versions of the DataEdgePlatform DataMosaix Private Cloud must prioritize the review of the vendor security advisory. Because this vulnerability allows for unauthorized administrative escalation within the platform, administrators should restrict access to project creation features until a definitive vendor patch is deployed to mitigate the risk of data compromise.

More Rockwell Automation CVEs

Sources