Rockwell Automation Vulnerability Allows Attackers to Execute Arbitrary Commands
ID: f396229b-5a6f-59ab-94c8-9f7cf243b445
STIX ID: report--f396229b-5a6f-59ab-94c8-9f7cf243b445
Feed Name: GBHackers
Threat Score
Rockwell Automation disclosed a critical vulnerability (CVE-2025-1449) in Verve Asset Manager’s Legacy Agentless Device Inventory feature that allows an attacker with administrative privileges to execute arbitrary commands within the service container; the issue (CVSS 3.1 score 9.1) affects versions up to 1.39 and is fixed in version 1.40. Organizations are urged to upgrade immediately and to monitor and restrict privileged access where upgrades cannot be applied immediately.
Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.
