CVE-2025-0477: Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0477?
CVE-2025-0477 is classified as a high-severity vulnerability due to its potential to allow password extraction.
How do I fix CVE-2025-0477?
To fix CVE-2025-0477, upgrade Rockwell Automation FactoryTalk® AssetCentre to version V15.00.001 or later.
What applications are affected by CVE-2025-0477?
CVE-2025-0477 affects all versions of Rockwell Automation FactoryTalk® AssetCentre prior to V15.00.001.
What type of vulnerability is CVE-2025-0477?
CVE-2025-0477 is an encryption vulnerability that arises from the use of weak encryption methodologies.
What could happen if CVE-2025-0477 is exploited?
If CVE-2025-0477 is exploited, a threat actor could potentially extract passwords belonging to other users of the application.