Unrated severityNVD Advisory· Published Jan 30, 2025· Updated Feb 12, 2025
Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability
CVE-2025-0498
Description
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
Affected products
2- Range: <15.00.001
- Rockwell Automation/FactoryTalk® AssetCentrev5Range: All prior to V15.00.001
Patches
0No patches discovered yet.
Vulnerability mechanics
AI mechanics synthesis has not run for this CVE yet.
References
1News mentions
0No linked articles in our index yet.