CVE-2025-9364

HIGH

FactoryTalk Analytics LogixAI - Exposure of Sensitive System Information via Over-Permissive Redis Instance

Title source: llm
STIX 2.1

Description

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential alteration of data.

Scores

CVSS v3 8.8
EPSS 0.0027
EPSS Percentile 18.3%
Attack Vector ADJACENT_NETWORK
CVSS:3.1/AV:A/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable no
Technical Impact total

Details

CWE
CWE-497
Status published
Products (2)
rockwellautomation/factorytalk_analytics_logixai 3.00.00
rockwellautomation/factorytalk_analytics_logixai 3.01.00
Published Sep 09, 2025
Tracked Since Feb 18, 2026