CVE-2025-7970

A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hijacking, or full communication compromise.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_activation_manager:*:*:*:*:*:*:*:*

History

17 Sep 2025, 15:59

Type Values Removed Values Added
CPE cpe:2.3:a:rockwellautomation:factorytalk_activation_manager:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : unknown
v3 : 7.5
First Time Rockwellautomation
Rockwellautomation factorytalk Activation Manager
References () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1741.html - () https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1741.html - Vendor Advisory

09 Sep 2025, 13:15

Type Values Removed Values Added
New CVE

Information

Published : 2025-09-09 13:15

Updated : 2025-09-17 15:59


NVD link : CVE-2025-7970

Mitre link : CVE-2025-7970

CVE.ORG link : CVE-2025-7970


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_activation_manager
CWE
CWE-306

Missing Authentication for Critical Function