An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
References
Link | Resource |
---|---|
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1748.html | Vendor Advisory |
Configurations
Configuration 1 (hide)
|
History
10 Sep 2025, 14:09
Type | Values Removed | Values Added |
---|---|---|
CPE | cpe:2.3:a:rockwellautomation:factorytalk_analytics_logixai:3.00.00:*:*:*:*:*:*:* cpe:2.3:a:rockwellautomation:factorytalk_analytics_logixai:3.01.00:*:*:*:*:*:*:* |
|
First Time |
Rockwellautomation factorytalk Analytics Logixai
Rockwellautomation |
|
CVSS |
v2 : v3 : |
v2 : unknown
v3 : 8.8 |
References | () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1748.html - Vendor Advisory |
09 Sep 2025, 13:15
Type | Values Removed | Values Added |
---|---|---|
New CVE |
Information
Published : 2025-09-09 13:15
Updated : 2025-09-10 14:09
NVD link : CVE-2025-9364
Mitre link : CVE-2025-9364
CVE.ORG link : CVE-2025-9364
JSON object : View
Products Affected
rockwellautomation
- factorytalk_analytics_logixai
CWE
CWE-497
Exposure of Sensitive System Information to an Unauthorized Control Sphere