Executive brief
Rockwell Automation's DataMosaix Private Cloud contains hardcoded URLs in source code that point directly to JSON files containing customer data, accessible without authentication. An attacker can retrieve this sensitive information without logging in, potentially exposing business-critical data stored in the industrial automation platform. The vulnerability was discovered internally and has been patched.
Technical details
A sensitive information exposure vulnerability exists in DataMosaix Private Cloud where hardcoded links in the source code reference JSON files that can be accessed without authentication. The vulnerability is classified as CWE-200 (Exposure of Sensitive Information to an Unauthorized Actor). The attack requires only network access to the affected system; no credentials or user interaction is needed. An unauthenticated remote attacker can directly reach these JSON files over the network and retrieve customer data. Rockwell Automation corrected this vulnerability in version 7.09, and no known public exploits in the wild have been reported.
Affected products
- Rockwell Automation DataMosaix Private Cloud <= 7.07
Timeline
- 2024-10-04: disclosed: Rockwell Automation SD1702 advisory published
- 2024-10-04: patched: Corrected in version 7.09