CVE-2018-19616 describes an authentication bypass vulnerability in Rockwell Automation Allen-Bradley PowerMonitor 1000, where client-side access control allows unauthenticated users to manage administrator accounts. This high-severity flaw (CVSS 8.1) has a network attack vector with high impact on confidentiality, integrity, and availability, despite high attack complexity. While not on the KEV or Hot List, an exploit is publicly available via ExploitDB, and it has garnered notable community discussion and media coverage.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
1408-em3a-ent_bCPE matchmatch criteria | cpe:2.3:o:rockwellautomation:powermonitor_1000_firmware:1408-em3a-ent_b:*:*:*:*:*:*:* |
CVSS version used by this source: 3.0
CVSS:3.0/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.