Rockwell Automation FactoryTalk Analytics LogixAI Over-Permissive Redis Database Vulnerability

Vulnerability

A database vulnerability has been identified in Rockwell Automation's FactoryTalk Analytics LogixAI, specifically in versions 3.00 and 3.01. The issue arises from an overly permissive Redis database instance, potentially allowing an intranet attacker to access and modify sensitive data.

Impact

Exploitation of this vulnerability could lead to unauthorized access to sensitive data and the ability to alter such data.

Remediation

Users of the affected software versions 3.00 and 3.01 should upgrade to version 3.02 or later. For those unable to upgrade, Rockwell Automation recommends following their security best practices.

Added: Sep 9, 2025, 1:16 PM
Updated: Sep 9, 2025, 4:49 PM

Vulnerability Rating

Custom Algorithm
spread
0.0
impact
5.0
exploitability
4.9
remediation
7.7
relevance
0.5
threat
0.0
urgency
2.9
incentive
1.7

Our algorithm analyzes dozens of metrics to generate these 8 key vulnerability categories, which are then combined to calculate the overall risk score.