CVE-2024-1156: Emerson Data Record Ad
High severity, CVSS 7.8. EPSS: 0.4% chance of exploitation in the next 30 days.
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
Affected products
- Emerson Data Record Ad: up to and including 2.0.1
- Emerson Flexlogger: up to and including 2022_q3
- Emerson G Web Development Software: up to and including 2022_q3
- Emerson Labview Nxg: version 5.1 only
- Emerson Specification Compliance Manager: up to and including 2023_q4
- Emerson Static Test Software Suite: up to and including 1.2
- Emerson Sts Software Bundle: up to and including 21.0
- Emerson Systemlink Server: before 2024_q1 (fixed in 2024_q1)
Published 2024-02-20. Last modified 2026-06-17.