CVE-2024-12371: Rockwell Automation PM1K 1408-BC3A-485
Critical severity, CVSS 9.3. EPSS: 0.5% chance of exploitation in the next 30 days.
A device takeover vulnerability exists in the Rockwell Automation Power Monitor 1000. This vulnerability allows configuration of a new Policyholder user without any authentication via API. Policyholder user is the most privileged user that can perform edit operations, creating admin users and performing factory reset.
Affected products
- Rockwell Automation PM1K 1408-BC3A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-BC3A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM1A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM1A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM2A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM2A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM3A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-EM3A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-TR1A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-TR1A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-TR2A-485: before v4.020 (fixed in v4.020)
- Rockwell Automation PM1K 1408-TR2A-Ent: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-TS3A-485: before 4.020 (fixed in 4.020)
- Rockwell Automation PM1K 1408-TS3A-Ent: before 4.020 (fixed in 4.020)
Published 2024-12-18. Last modified 2026-06-17.