CVE-2024-6078: Rockwell Automation Datamosaix
High severity, CVSS 8.6. EPSS: 0.4% chance of exploitation in the next 30 days.
CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.
Affected products
- Rockwell Automation Datamosaix: version 7.07 only
- Rockwellautomation Datamosaix: before 7.07 (fixed in 7.07)
Published 2024-08-14. Last modified 2026-06-17.