CVE-2025-11697

HIGH

Studio 5000 Simulation Interface - Path Traversal

Title source: llm
STIX 2.1

Description

A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.

Scores

CVSS v4 8.9
EPSS 0.0013
EPSS Percentile 2.6%
CVSS:4.0/AV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-200
Status published
Products (1)
Rockwell Automation/Studio 5000 ® Simulation Interface 2.02 and prior
Published Nov 11, 2025
Tracked Since Feb 18, 2026