An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.
Analysis and contextual insights are available on OpenCVE Cloud.
Vendor Solution
Upgrade to V7.09
Tracking
Sign in to view the affected projects.
| Source | ID | Title |
|---|---|---|
EUVD |
EUVD-2024-47236 | CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud. |
Mon, 19 Aug 2024 19:30:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| First Time appeared |
Rockwellautomation
Rockwellautomation datamosaix |
|
| CPEs | cpe:2.3:a:rockwellautomation:datamosaix:*:*:*:*:*:*:*:* | |
| Vendors & Products |
Rockwellautomation
Rockwellautomation datamosaix |
|
| Metrics |
ssvc
|
Wed, 14 Aug 2024 20:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud. | |
| Title | Rockwell Automation Authentication Bypass Vulnerability in DataMosaix™ | |
| Weaknesses | CWE-287 | |
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2024-08-19T18:43:37.917Z
Reserved: 2024-06-17T16:31:04.293Z
Link: CVE-2024-6078
Updated: 2024-08-19T18:43:32.525Z
Status : Deferred
Published: 2024-08-14T20:15:12.780
Modified: 2026-04-15T00:35:42.020
Link: CVE-2024-6078
No data.
OpenCVE Enrichment
No data.
EUVD