CVE-2025-7970
Last modified
CVE-2025-7970 is a high-severity vulnerability rated 8.7/10 on the CVSS scale. A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. EPSS estimates a 0.34% chance of exploitation in the next 30 days.
Description
A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.
Metrics
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N
CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:H/VI:N/VA:N/SC:N/SI:N/SA:N/E:X/CR:X/IR:X/AR:X/MAV:X/MAC:X/MAT:X/MPR:X/MUI:X/MVC:X/MVI:X/MVA:X/MSC:X/MSI:X/MSA:X/S:X/AU:X/R:X/V:X/RE:X/U:X
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Rockwellautomation | Factorytalk Activation Manager | >= 5.00.00, <= 5.01.01 |
References
Timeline
- Published
- Last Modified
- Status
- Analyzed
Frequently Asked Questions
What is CVE-2025-7970?
How severe is CVE-2025-7970?
How do I fix CVE-2025-7970?
Are you affected by CVE-2025-7970?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
