CVE-2025-14377

HIGH

Verve Asset Manager - Info Disclosure

Title source: llm
STIX 2.1

Description

A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.

Scores

CVSS v4 8.8
EPSS 0.0002
EPSS Percentile 6.7%
CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-312
Status published
Products (1)
Rockwell Automation/Verve Asset Manager 1.33 1.34 1.35 1.36 1.37 1.38 1.39 1.40 1.41 1.41.1 1.41.2 1.41.3
Published Jan 20, 2026
Tracked Since Feb 18, 2026