CVE-2025-9364

HIGH

Redis - Info Disclosure

Title source: llm
STIX 2.1

Description

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

Scores

CVSS v3 8.8
EPSS 0.0002
EPSS Percentile 5.2%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-497
Status published
Products (2)
rockwellautomation/factorytalk_analytics_logixai 3.00.00
rockwellautomation/factorytalk_analytics_logixai 3.01.00
Published Sep 09, 2025
Tracked Since Feb 18, 2026