HIGH
Rockwell Automation FactoryTalk® Analytics™ LogixAI® Exposed Redis DB
Published Sep 9, 2025
8.7
HIGHCVSS 4.0
EPSS 0.29%
Description
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.
Affected products
-
Affected
- Versions 3.00 and 3.01
Default status is the baseline for the product. Each version can override it (patched versions can be marked unaffected).
| Vendor | Product | Default status | Versions |
|---|---|---|---|
| Rockwell Automation | FactoryTalk® Analytics™ LogixAI® | unaffected | Affected
|
OR
- 3.00.00
- 3.01.00
No data.
No Red Hat product state for this CVE.
No package ranges for this CVE.
Remediation
Vendor solution
Upgrade to
Version 3.02 and later
Weaknesses (1)
References (2)
- https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-27251 Advisory
- https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1748.html Vendor Advisory
| Link | Providers | Tags |
|---|---|---|
| https://euvd.enisa.europa.eu/vulnerability/EUVD-2025-27251 | Advisory | |
| https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1748.html | Vendor Advisory |
Change history (0)
No recorded changes yet.
Sources
CVE.org / MITRE
Status PUBLISHED
Assigner Rockwell
Published Sep 9, 2025
Updated Sep 9, 2025
Reserved Aug 22, 2025
Link CVE-2025-9364
CISA Vulnrichment
Updated Sep 9, 2025
Red Hat
No data
GitHub
No data