Cyber Resilience

CVE-2024-8533

High

Published: 12 September 2024

Published
12 September 2024
Modified
19 September 2024
KEV Added
Patch
CVSS Score v4 7.7 CVSS:4.0/AV:N/AC:H/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
EPSS Score 0.0009 25.9th percentile
Risk Priority 15 60% EPSS · 20% KEV · 20% CVSS

Summary

CVE-2024-8533 is a high-severity Improper Privilege Management (CWE-269) vulnerability in Rockwellautomation 2800C Optixpanel Compact Firmware. Its CVSS base score is 7.7 (High).

Operationally, ranked at the 25.9th percentile by exploit likelihood (below the median); it is not currently listed in the CISA KEV catalog.

EU & UK References

Vulnerability details

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfiltrate credentials and escalate privileges.

CWE(s)

Related Threats

No named actor attribution yet. ATT&CK technique mapping in progress for this CVE.

Affected Assets

rockwellautomation
2800c optixpanel compact firmware
4.0.0.325 — 4.0.2.116
rockwellautomation
2800s optixpanel standard firmware
4.0.0.350 — 4.0.2.123
rockwellautomation
embedded edge compute module firmware
4.0.0.347 — 4.0.2.106

Mitigating Controls

Likely Mitigating Controls AI

Per-CVE control mapping for this CVE has not run yet; the list below is derived from the weakness types (CWEs) cited in the NVD entry.

addresses: CWE-269 CWE-276

Policy addresses roles, responsibilities, and privilege management to prevent improper privilege assignments.

addresses: CWE-269 CWE-276

Implements core proper privilege management by restricting to only required rights.

addresses: CWE-269 CWE-276

Baseline configuration documents and controls privilege assignments, making improper privilege management harder to introduce or sustain.

addresses: CWE-276 CWE-269

Requiring the most restrictive settings instead of defaults prevents incorrect default permissions on resources.

addresses: CWE-269 CWE-276

Defines roles and responsibilities to ensure proper privilege management during configuration changes.

addresses: CWE-269 CWE-276

Designates roles and review processes for managing physical privileges and access rights.

addresses: CWE-276 CWE-269

Tailoring explicitly overrides or scopes default permission assignments in the baseline to match the system's actual risk and operational needs.

addresses: CWE-269 CWE-276

Centralized privilege assignment and oversight prevent ad-hoc or excessive privilege grants that occur when each system is configured independently.

References