First published: Thu Jan 30 2025(Updated: )
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
Credit: PSIRT@rockwellautomation.com
Affected Software | Affected Version | How to fix |
---|---|---|
Rockwell Automation FactoryTalk AssetCentre | <V15.00.001 |
Corrected in: V11, V12, and V13 (patch available) V15.00.01 and later
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2025-0497 has been classified as a data exposure vulnerability that poses significant security risks.
CVE-2025-0497 affects all versions of Rockwell Automation FactoryTalk AssetCentre prior to V15.00.001.
To mitigate CVE-2025-0497, upgrade Rockwell Automation FactoryTalk AssetCentre to version V15.00.001 or later.
CVE-2025-0497 exposes sensitive credentials due to improper storage in configuration files.
There are no official workarounds for CVE-2025-0497, so upgrading is the recommended course of action.