Rewterz
Rewterz Threat Advisory – Multiple Fortinet Products Vulnerabilities
September 15, 2023
Rewterz
Rewterz Threat Advisory – CVE-2023-41267 – Apache Airflow HDFS Provider Vulnerability
September 18, 2023

Rewterz Threat Advisory – ICS: Rockwell Automation Pavilion8 Vulnerability

Severity

High

Analysis Summary

CVE-2023-29463

Rockwell Automation Pavilion8 could allow a remote authenticated attacker to bypass security restrictions, caused by improper authentication validation by the JMX Console. By sending a specially crafted request, an attacker could exploit this vulnerability to retrieve other application users’ session data and or log users out of their sessions.

Impact

  • Security Bypass

Indicators Of Compromise

CVE

  • CVE-2023-29463

Affected Vendors

Rockwell Automation

Affected Products

  • Rockwell Automation Pavilion8 5.17.00
  • Rockwell Automation Pavilion8 5.17.01

Remediation

Upgrade to the latest version of Pavilion, available from the Rockwell Automation Web site.

Rockwell Automation Web site