Security Flaw in Rockwell Automation's 5032 Digital Configurable Module
CVE-2025-7774

8.8HIGH

What is CVE-2025-7774?

A security issue has been identified in the 5032 16pt Digital Configurable module's web server that enables attackers to intercept session credentials. This flaw allows unauthorized individuals to exploit managed sessions for a brief window of three minutes, potentially executing privileged actions. Effective measures should be taken to address this vulnerability and enhance the security of the affected product.

Affected Version(s)

5032-CFGB16M12DR 1.011

5032-CFGB16M12M12LDR 1.011

5032-CFGB16M12P5DR 1.011

References

CVSS V4

Score:
8.8
Severity:
HIGH
Confidentiality:
Low
Integrity:
Low
Availability:
High
Attack Vector:
Network
Attack Complexity:
Low
Attack Required:
None
Privileges Required:
Undefined
User Interaction:
None

Timeline

  • Vulnerability published

  • Vulnerability Reserved

.