logo

Rockwell Automation Vulnerability Allows Attackers to Execute Arbitrary Commands

ID: f396229b-5a6f-59ab-94c8-9f7cf243b445

STIX ID: report--f396229b-5a6f-59ab-94c8-9f7cf243b445

Feed Name: GBHackers

Threat Score
72/100

Date Published: 2025-04-01

Date Updated: 2026-04-22

Author: Divya

...
...

Rockwell Automation disclosed a critical vulnerability (CVE-2025-1449) in Verve Asset Manager’s Legacy Agentless Device Inventory feature that allows an attacker with administrative privileges to execute arbitrary commands within the service container; the issue (CVSS 3.1 score 9.1) affects versions up to 1.39 and is fixed in version 1.40. Organizations are urged to upgrade immediately and to monitor and restrict privileged access where upgrades cannot be applied immediately.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.