CVE-2023-2072 - CVE House
Back to Database
Status published High CVE-2023-2072

Rockwell Automation PowerMonitor 1000 Cross-Site Scripting Vulnerability

Vulnerability Description

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pages do not require privileges to access and can be injected with code by an attacker which could be used to leverage an attack on an authenticated user resulting in remote code execution and potentially the complete loss of confidentiality, integrity, and availability of the product.

Impact Analysis

Refer to official advisory for detailed impact metrics.

Remediation

Ensure systems are updated to the latest vendor-supplied patch levels.

THREAT MONITOR

Am I Vulnerable?

Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2023-2072

Credits & Attribution

No credits recorded in the NVD database.

Affected Vendor

Rockwell Automation

View all reports →

Affected Software

PowerMonitor 1000
Vulnerable Versions:
V4.011

Timeline

Official Publish: July 11th, 2023
Last Modified: November 7th, 2024
Added to House: July 22nd, 2026

CVSS Vectors

V3: CVSS:3.1/AV:N/AC:L/PR:N/UI:R/S:U/C:H/I:H/A:H

Weaknesses (CWE)