VYPR

FactoryTalk AssetCentre

by Rockwellautomation

CVEs (3)

  • CVE-2025-0477Jan 30, 2025
    risk 0.00cvss epss 0.01

    An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.

  • CVE-2025-0497Jan 30, 2025
    risk 0.00cvss epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.

  • CVE-2025-0498Jan 30, 2025
    risk 0.00cvss epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.