{"cve":{"cve_id":"CVE-2024-6435","is_kev":false,"kev_date_added":null,"kev_vendor_project":null,"kev_product":null,"kev_vulnerability_name":null,"kev_short_description":null,"kev_required_action":null,"kev_due_date":null,"kev_known_ransomware":null,"kev_notes":null,"kev_cwes":null,"epss_score":0.00488,"epss_percentile":0.38167,"epss_as_of":"2026-06-23","description":"A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileges. If exploited, an attacker could read sensitive data, and create users. For example, a malicious user with basic privileges could perform critical functions such as creating a user with elevated privileges and reading sensitive information in the “views” section.","published_at":"2024-07-16T13:00:42.859000Z","last_modified_at":null,"cvss_v3_score":null,"cvss_v3_vector":null,"cvss_v3_severity":null,"cvss_v4_score":8.7,"cvss_v4_vector":"CVSS:4.0/AV:N/AC:L/AT:N/PR:L/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N","cvss_v4_severity":"HIGH","ssvc_decision":null,"ssvc_exploitation":"none","ssvc_automatable":false,"ssvc_technical_impact":"partial","cwes":["CWE-732"],"nvd_references":["https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1681.html"],"vuln_status":null,"trending_score":null,"is_trending":false,"has_trended":false,"trended_number_one":false,"trending_peak_score":null,"trending_peak_rank":null,"started_trending_at":null,"trended_number_one_at":null,"summary_generated":null,"summary_generated_at":null,"summary_model":null,"created_at":"2026-06-24T00:09:39.878444Z","updated_at":"2026-06-29T02:20:07.496563Z"},"effective_severity":"HIGH","badges":[],"impact_analysis":[],"cvss_v3_decoded":{"version":null,"metrics":[]},"cvss_v4_decoded":{"version":"4.0","metrics":[{"metric":"AV","name":"Attack Vector","value":"N","value_label":"Network"},{"metric":"AC","name":"Attack Complexity","value":"L","value_label":"Low"},{"metric":"AT","name":"Attack Requirements","value":"N","value_label":"None"},{"metric":"PR","name":"Privileges Required","value":"L","value_label":"Low"},{"metric":"UI","name":"User Interaction","value":"N","value_label":"None"},{"metric":"VC","name":"Confidentiality (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VI","name":"Integrity (Vulnerable System)","value":"H","value_label":"High"},{"metric":"VA","name":"Availability (Vulnerable System)","value":"H","value_label":"High"},{"metric":"SC","name":"Confidentiality (Subsequent System)","value":"N","value_label":"None"},{"metric":"SI","name":"Integrity (Subsequent System)","value":"N","value_label":"None"},{"metric":"SA","name":"Availability (Subsequent System)","value":"N","value_label":"None"}]},"affected":[{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.15.00","version_start_inclusive":true,"version_end":"5.15.00","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.15.00:5.15.00"},{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.15.01","version_start_inclusive":true,"version_end":"5.15.01","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.15.01:5.15.01"},{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.16.00","version_start_inclusive":true,"version_end":"5.16.00","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.16.00:5.16.00"},{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.17.00","version_start_inclusive":true,"version_end":"5.17.00","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.17.00:5.17.00"},{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.17.01","version_start_inclusive":true,"version_end":"5.17.01","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.17.01:5.17.01"},{"vendor_slug":"rockwell-automation","vendor_name":"Rockwell Automation","product_slug":"pavilion8","product_name":"Pavilion8®","version_start":"5.20.00","version_start_inclusive":true,"version_end":"5.20.00","version_end_inclusive":true,"cpe23_uri":"cve5:rockwell-automation:pavilion8:5.20.00:5.20.00"}],"exploit_refs":[],"news":[],"references":[{"url":"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1681.html","source_type":"VENDOR_ADVISORY","tags":["advisory"]}],"timeline":[{"type":"published","at":"2024-07-16T13:00:42.859000Z","label":"CVE published","source":null},{"type":"cvss_changed","at":"2026-06-28T17:39:59.661105Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:39:59.661105Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"cvss_changed","at":"2026-06-28T17:39:59.661105Z","label":"CVSS score revised","source":"cvelistv5"},{"type":"ssvc_changed","at":"2026-06-29T02:20:07.496563Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T02:20:07.496563Z","label":"SSVC decision revised","source":"vulnrichment"},{"type":"ssvc_changed","at":"2026-06-29T02:20:07.496563Z","label":"SSVC decision revised","source":"vulnrichment"}]}