Summary
CVE-2024-7952 is a sensitive data exposure vulnerability in Rockwell Automation’s DataEdgePlatform DataMosaix™ Private Cloud. The application contains hardcoded links in its source code that point to JSON files reachable without any authentication, allowing an unauthenticated network attacker to view customer data. The vulnerability affects version 7.07 and earlier and carries a high severity rating.
Technical details
- Root cause: hardcoded links embedded in the application source code reference JSON files/endpoints that are not protected by authentication checks.
- Trigger conditions: no credentials, prior access, or user interaction are required — an attacker only needs network reachability to the affected endpoints.
- Attack vector: Network (AV:N), low attack complexity, no privileges or user interaction required.
- Impact: disclosure of customer data via direct access to the exposed JSON files; no reported impact to integrity or availability.
Affected software
- Rockwell Automation DataEdgePlatform DataMosaix™ Private Cloud — version 7.07 and earlier.
Severity
- CVSS v4.0 Base Score: 8.7 (High) —
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N - CVSS v3.1 Base Score: 7.5 (High) —
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N - Weakness classification: CWE-798 (Use of Hard-coded Credentials)
Mitigation and recommended actions
- Immediate: upgrade DataMosaix Private Cloud to version 7.09, which contains the fix.
- If unable to patch immediately: no workaround is currently published; restrict network exposure of the application (place it behind a firewall/VPN, remove it from direct internet access) and follow general security best practices while prioritizing remediation, informed by environment-specific risk assessment (e.g., SSVC).
How IONIX identifies potentially affected assets
IONIX matches the following signals against data already collected when it crawled the asset; identifying the technology sends no request beyond that crawl.
- Page title:
FactoryTalk DataMosaix Private Cloud - Favicon fingerprint: exact hash match
-1389597322

