Vulnerability Monitor

The vendors, products, and vulnerabilities you care about

CVE-2025-0477


An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.


Published

2025-01-30T18:15:31.893

Last Modified

2025-11-04T17:29:22.247

Status

Analyzed

Source

[email protected]

Severity

CVSSv3.1: 9.8 (CRITICAL)

Weaknesses
  • Type: Secondary
    CWE-522

Affected Vendors & Products
Type Vendor Product Version/Range Vulnerable?
Application rockwellautomation factorytalk_assetcentre < 15.00.01 Yes

References