CRITICAL✓ PATCH🇵🇱 Wersja polska

CVE-2025-0477

CVSS 9.3v4.0pub. 2025-01-30upd. 2025-11-04

An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.

🤖 AI Analysis
How it works

The vulnerability (CWE-522 — Insufficiently Protected Credentials) results from the use of a weak encryption algorithm or mechanism for storing user application passwords. An attacker who gains access to encrypted authentication data can – due to the weakness of the applied method – reverse or break the encryption and recover passwords in plain text. This process does not require authentication or user interaction, making the attack possible to conduct remotely.

Impact

An attacker can extract passwords of other users of the FactoryTalk® AssetCentre application, which may lead to unauthorized access to the industrial asset management system and potential compromise of confidentiality, integrity, and availability of data in the OT environment.

Mitigation & patch

Update Rockwell Automation FactoryTalk® AssetCentre software to version V15.00.001 or later. Detailed information is available in the manufacturer's security bulletin at: https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1721.html

Who is affected

All versions of Rockwell Automation FactoryTalk® AssetCentre prior to V15.00.001

Analysis generated by Claude AI (Anthropic) based on NVD data. Always verify with vendor.
CVSS Vector
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
  • Rockwellautomation Factorytalk Assetcentre

    APP
    Rockwellautomation
    < 15.00.01
🟢
PATCH AVAILABLE
Vendor update available. Deploy in standard maintenance cycle.
CWE
References

Related vulnerabilities

CVE-2021-27462CRITICAL10.0PL ✓same product

RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27464CRITICAL10.0PL ✓same product

SQLi bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27466CRITICAL10.0PL ✓same product

RCE przez niebezpieczną deserializację w Rockwell FactoryTalk AssetCentre

CVE-2021-27468CRITICAL10.0PL ✓same product

SQL Injection bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27460CRITICAL10.0PL ✓same product

Niebezpieczna deserializacja w Rockwell FactoryTalk AssetCentre — pełny dostęp bez uwierzytelnienia