CVE-2025-9364: Rockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DB
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2025-9364?
CVE-2025-9364 is considered a high-severity vulnerability due to the risk of unauthorized access to sensitive data.
How do I fix CVE-2025-9364?
To fix CVE-2025-9364, you should configure your Redis instance to restrict permissions and limit access to trusted users only.
What products are affected by CVE-2025-9364?
CVE-2025-9364 affects the Rockwell Automation FactoryTalk Analytics LogixAI product.
What are the risks associated with CVE-2025-9364?
The risks associated with CVE-2025-9364 include unauthorized access to sensitive data and potential data alteration.
Is there a workaround for CVE-2025-9364?
Currently, the recommended workaround for CVE-2025-9364 is to implement strict access controls on the Redis instance.