A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.
History

Tue, 09 Sep 2025 14:15:00 +0000

Type Values Removed Values Added
Metrics ssvc

{'options': {'Automatable': 'yes', 'Exploitation': 'none', 'Technical Impact': 'partial'}, 'version': '2.0.3'}


Tue, 09 Sep 2025 13:00:00 +0000

Type Values Removed Values Added
Description A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.
Title Rockwell Automation FactoryTalk Activation Manager Lack of Encryption Vulnerability
Weaknesses CWE-306
References
Metrics cvssV4_0

{'score': 8.7, 'vector': 'CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N'}


cve-icon MITRE

Status: PUBLISHED

Assigner: Rockwell

Published:

Updated: 2025-09-09T13:35:17.769Z

Reserved: 2025-07-21T19:00:46.407Z

Link: CVE-2025-7970

cve-icon Vulnrichment

Updated: 2025-09-09T13:35:14.380Z

cve-icon NVD

Status : Awaiting Analysis

Published: 2025-09-09T13:15:31.963

Modified: 2025-09-09T16:28:43.660

Link: CVE-2025-7970

cve-icon Redhat

No data.

cve-icon OpenCVE Enrichment

No data.