CVE-2025-11696

HIGH

Studio 5000 Simulation Interface - SSRF

Title source: llm
STIX 2.1

Description

A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.

Scores

CVSS v4 8.9
EPSS 0.0015
EPSS Percentile 4.5%
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-22
Status published
Products (1)
Rockwell Automation/Studio 5000® Simulation Interface™ 2.02 and prior
Published Nov 11, 2025
Tracked Since Feb 18, 2026