Vulnerability Description
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.
CVSS Score
HIGH
Affected Products
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Powermonitor 1000 Firmware | - |
| Rockwellautomation | Powermonitor 1000 | - |
Related Weaknesses (CWE)
References
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139761Permissions RequiredVendor Advisory
- https://rockwellautomation.custhelp.com/app/answers/answer_view/a_id/1139761Permissions RequiredVendor Advisory
FAQ
What is CVE-2023-2072?
CVE-2023-2072 is a vulnerability with a CVSS score of 8.8 (HIGH). The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be ...
How severe is CVE-2023-2072?
CVE-2023-2072 has been rated HIGH with a CVSS base score of 8.8/10. Review the CVSS metrics above for detailed severity breakdown.
Is there a patch for CVE-2023-2072?
Check the references section above for vendor advisories and patch information. Affected products include: Rockwellautomation Powermonitor 1000 Firmware, Rockwellautomation Powermonitor 1000.