Rockwell Automation FactoryTalk® AssetCentre
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*
- < V15.00.001
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk AssetCentre. This vulnerability arises from the insecure storage of credentials in the configuration files of certain packages, which could allow unauthorized access to sensitive information.
Exploitation of this vulnerability could lead to unauthorized access to stored credentials, allowing an attacker to impersonate users or access sensitive data.
Users are advised to update FactoryTalk AssetCentre to V15.00.01 or later. For those on legacy versions, patches are available through the Rockwell Automation January 2025 Monthly Patch rollup or by following specific instructions for certain packages.
Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.