CVE-2023-29463: Rockwellautomation PAVILION8
Medium severity, CVSS 5.4. EPSS: 1.5% chance of exploitation in the next 30 days.
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session data and or log users out of their session.
Affected products
- Rockwellautomation PAVILION8: before 5.20 (fixed in 5.20)
Published 2023-09-12. Last modified 2026-06-17.