CVE-2025-0659
HIGHRockwell Automation DataEdge Platform - Path Traversal
Title source: llmDescription
A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects.
References (1)
Core 1
Core References
Scores
CVSS v4
7.0
EPSS
0.0036
EPSS Percentile
27.8%
CVSS:4.0/AV:N/AC:L/AT:N/PR:H/UI:N/VC:H/VI:L/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
CISA SSVC
Vulnrichment
Exploitation
none
Automatable
yes
Technical Impact
partial
Details
CWE
CWE-200
Status
published
Products (1)
Rockwell Automation/DataEdgePlatform DataMosaix™ Private Cloud
<=7.11
Published
Jan 28, 2025
Tracked Since
Feb 18, 2026