Show filters
40 Total Results
Displaying 1-10 of 40
Sort by:
Attacker Value
Unknown
CVE-2025-0498
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
0
Attacker Value
Unknown
CVE-2025-0497
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
0
Attacker Value
Unknown
CVE-2025-0477
Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
0
Attacker Value
Unknown
CVE-2025-24482
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
0
Attacker Value
Unknown
CVE-2025-24481
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.
0
Attacker Value
Unknown
CVE-2025-24480
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.
0
Attacker Value
Unknown
CVE-2025-24479
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
0
Attacker Value
Unknown
CVE-2025-24478
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.
0
Attacker Value
Unknown
CVE-2025-0631
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
0
Attacker Value
Unknown
CVE-2025-0659
Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A path
traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character
sequence in the body of the vulnerable endpoint, it is possible to overwrite
files outside of the intended directory. A threat actor with admin privileges could
leverage this vulnerability to overwrite reports including user projects.
0