Path Traversal Vulnerability in Rockwell Automation DataEdge Platform
CVE-2025-0659
7HIGH
Key Information:
- Vendor
- Rockwell Automation
- Vendor
- CVE Published:
- 28 January 2025
Summary
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud, enabling threat actors with admin privileges to exploit the vulnerable endpoint. By providing a specific character sequence in the request body, these actors can manipulate the file system, leading to the potential overwriting of sensitive files, including user reports and projects, beyond the intended directory. This vulnerability poses risks for data integrity and security, necessitating immediate attention from administrators.
Affected Version(s)
DataEdgePlatform DataMosaix™ Private Cloud <=7.11
References
CVSS V4
Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None
Timeline
Vulnerability published
Vulnerability Reserved