CVE-2025-0498: Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-0498?
CVE-2025-0498 is considered a high-severity vulnerability due to the potential for data exposure and unauthorized impersonation.
How do I fix CVE-2025-0498?
To fix CVE-2025-0498, update Rockwell Automation FactoryTalk® AssetCentre to version V15.00.001 or later.
What are the implications of CVE-2025-0498?
The implications of CVE-2025-0498 include the risk of a threat actor stealing user tokens to impersonate legitimate users.
Which versions of Rockwell Automation FactoryTalk® AssetCentre are affected by CVE-2025-0498?
All versions of Rockwell Automation FactoryTalk® AssetCentre prior to V15.00.001 are affected by CVE-2025-0498.
What kind of attacks can exploit CVE-2025-0498?
CVE-2025-0498 can be exploited through attacks that involve stealing user tokens to gain unauthorized access or impersonate other users.