Show filters
40 Total Results
Displaying 1-10 of 40
Sort by:
Attacker Value
Unknown

CVE-2025-0498

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
0
Attacker Value
Unknown

CVE-2025-0497

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
0
Attacker Value
Unknown

CVE-2025-0477

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
0
Attacker Value
Unknown

CVE-2025-24482

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Injection Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect default permissions and allows for DLLs to be executed with higher level permissions.
0
Attacker Value
Unknown

CVE-2025-24481

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.
0
Attacker Value
Unknown

CVE-2025-24480

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Remote Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to lack of input sanitation and could allow a remote attacker to run commands or code as a high privileged user.
0
Attacker Value
Unknown

CVE-2025-24479

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Local Code Execution Vulnerability exists in the product and version listed above. The vulnerability is due to a default setting in Windows and allows access to the Command Prompt as a higher privileged user.
0
Attacker Value
Unknown

CVE-2025-24478

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.
0
Attacker Value
Unknown

CVE-2025-0631

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A Credential Exposure Vulnerability exists in the above-mentioned product and version. The vulnerability is due to using HTTP resulting in credentials being sent in clear text.
0
Attacker Value
Unknown

CVE-2025-0659

Disclosure Date: January 28, 2025 (last updated January 29, 2025)
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.
0