You can’t make this stuff up.
"An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute for a BUTTON element." cve.circl.lu/cve/CVE-2018-19…

Dec 27, 2018 · 11:16 PM UTC