An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
History

Wed, 10 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation factorytalk Analytics Logixai
CPEs cpe:2.3:a:rockwellautomation:factorytalk_analytics_logixai:3.00.00:*:*:*:*:*:*:*
cpe:2.3:a:rockwellautomation:factorytalk_analytics_logixai:3.01.00:*:*:*:*:*:*:*
Vendors & Products Rockwellautomation factorytalk Analytics Logixai
Metrics cvssV3_1

{'score': 8.8, 'vector': 'CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H'}


Wed, 10 Sep 2025 09:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'no', 'Exploitation': 'none', 'Technical Impact': 'total'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 21:45:00 +0000

Type Values Removed Values Added
First Time appeared Rockwellautomation
Rockwellautomation factorytalk
Vendors & Products Rockwellautomation
Rockwellautomation factorytalk

Tue, 09 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
Title Rockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DB
Weaknesses CWE-497
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:A/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published: 2025-09-09T12:41:23.124Z

Updated: 2025-09-09T13:36:31.291Z

Reserved: 2025-08-22T15:52:49.830Z

Link: CVE-2025-9364

cve-icon Vulnrichment

Updated: 2025-09-09T13:36:27.725Z

cve-icon NVD

Status : Analyzed

Published: 2025-09-09T13:15:33.237

Modified: 2025-09-10T14:09:05.267

Link: CVE-2025-9364

cve-icon Redhat

No data.