← voltar
CVE-2025-0659

Path Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private Cloud

CVSS 7 HIGHEPSS 0.4%CWE-200
Vexday Risk Score
21Baixo
Decisão SSVC (CISA)
Track
Sem sinal de exploração → monitorar
CVSS 7EPSS 0.4%KEV nãoPoC Nuclei Metasploit Patch
Ciclo de vida
28 jan 2025Publicada no NVD
Recomendação: Monitorar — sem sinal de exploração no momento.
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N

Quer saber se a sua infraestrutura está exposta a isto?

Falar com a TrueHacking →