Path Traversal Vulnerability in Rockwell Automation DataEdge Platform
CVE-2025-0659

7HIGH

Key Information:

Vendor
CVE Published:
28 January 2025

Summary

A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud, enabling threat actors with admin privileges to exploit the vulnerable endpoint. By providing a specific character sequence in the request body, these actors can manipulate the file system, leading to the potential overwriting of sensitive files, including user reports and projects, beyond the intended directory. This vulnerability poses risks for data integrity and security, necessitating immediate attention from administrators.

Affected Version(s)

DataEdgePlatform DataMosaix™ Private Cloud <=7.11

References

CVSS V4

Score:
7
Severity:
HIGH
Confidentiality:
High
Integrity:
Low
Availability:
None
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.