Vulnerability Details CVE-2025-0497
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.001
EPSS Ranking 16.4%
CVSS Severity
CVSS v3 Score 9.8
Products affected by CVE-2025-0497
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:-
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:11.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:12.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:13.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:5.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.10.01
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:8.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:9.00.00