CVE-2025-9036 HIGH

CVE-2025-9036: Rockwell Automation FactoryTalk® Action Manager v1.0.0 Runtime Vulnerability

Vendor Rockwell Automation
Product FactoryTalk® Action Manager
Weakness CWE-200 · Info exposure
Published August 14, 2025
Last update August 14, 2025

CVSS base score

8.5/10
Attack vector Local
Attack complexity Low
Privileges required None
User interaction
Confidentiality
Integrity

CVSS vector

CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:P/VC:H/VI:H/VA:H/SC:N/SI:N/SA:N

What the vulnerability does

01Description

A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.

Key dates

02Disclosure timeline

August 14, 2025 CVE published
August 14, 2025 Record updated

Related vulnerabilities

04Related CVE