Analysis and contextual insights are available on OpenCVE Cloud.
No vendor fix or workaround currently provided.
Additional remediation guidance may be available on OpenCVE Cloud.
Tracking
Sign in to view the affected projects.
No advisories yet.
Tue, 01 Sep 2026 14:00:00 +0000
| Type | Values Removed | Values Added |
|---|---|---|
| Description | A security issue exists within the Redundancy Module Configuration Tool. The RMConfigTool.exe binary searches directories in the system path for a required DLL, and one or more of these directories may be writable by standard (non-administrator) users due to incorrect default permissions. If a local attacker places a malicious DLL in such a directory and an administrator subsequently runs the tool, the malicious DLL is loaded into the elevated process and executes with Administrator/SYSTEM privileges. | |
| Title | Redundancy Module Configuration Tool - Multiple Vulnerabilities | |
| First Time appeared |
Rockwell Automation
Rockwell Automation redundancy Module Configuration Tool |
|
| Weaknesses | CWE-276 | |
| CPEs | cpe:2.3:a:rockwell_automation:redundancy_module_configuration_tool:10.00.00:*:*:*:*:*:*:* | |
| Vendors & Products |
Rockwell Automation
Rockwell Automation redundancy Module Configuration Tool |
|
| References |
| |
| Metrics |
cvssV4_0
|
Status: PUBLISHED
Assigner: Rockwell
Published:
Updated: 2026-09-01T15:50:00.801Z
Reserved: 2026-05-26T17:51:46.936Z
Link: CVE-2026-9634
No data.
Status : Received
Published: 2026-09-01T14:17:50.017
Modified: 2026-09-01T16:17:40.120
Link: CVE-2026-9634
No data.
OpenCVE Enrichment
No data.
-
CWE-276
Incorrect Default Permissions