Security Advisory

CVE-2025-1449

CVE vulnerability detail - eXtreme Datacenter Security Operations

Published 2025-03-31 16:00:56
Last updated 2025-03-31 18:24:38
Assigner Rockwell
CVSS score 7.5
State PUBLISHED

Description

A vulnerability exists in the Rockwell Automation Verve Asset Manager due to insufficient variable sanitizing. A portion of the administrative web interface for Verve's Legacy Agentless Device Inventory (ADI) capability (deprecated since the 1.36 release) allows users to change a variable with inadequate sanitizing. If exploited, it could allow a threat actor with administrative access to run arbitrary commands in the context of the container running the service.