Vulnerability Details CVE-2025-0477
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.002
EPSS Ranking 43.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-0477
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:-
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:11.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:12.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:13.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:5.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.10.01
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:8.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:9.00.00