CVE-2025-14376

HIGH

Verve Asset Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.

Scores

CVSS v4 8.6
EPSS 0.0002
EPSS Percentile 5.4%
CVSS:4.0/AV:L/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:N/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-922
Status published
Products (1)
Rockwell Automation/Verve Asset Manager 1.33 1.34 1.35 1.36 1.37 1.38 1.39 1.40 1.41 1.41.1 1.41.2 1.41.3
Published Jan 20, 2026
Tracked Since Feb 18, 2026