You can’t make this stuff up.
"An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element."
cve.circl.lu/cve/CVE-2018-19…
Dec 27, 2018 · 11:16 PM UTC
