CVE-2025-9364
8.8Rockwell Automation · FactoryTalk Analytics LogixAI
A misconfigured Redis instance in Rockwell Automation FactoryTalk Analytics LogixAI allows unauthorized network users to access or modify sensitive system information.
Executive summary
A critical security vulnerability in Rockwell Automation FactoryTalk Analytics LogixAI enables unauthenticated network attackers to access or alter sensitive data due to an over permissive Redis instance.
Vulnerability
The vulnerability is an exposure of sensitive system information caused by an over permissive Redis instance (CWE-497). This flaw allows an unauthenticated attacker present on the local intranet to access or potentially modify sensitive data managed by the application.
Business impact
The exposure of sensitive data and the potential for unauthorized data modification pose a significant risk to operational integrity and data confidentiality. Given the high CVSS score of 8.8, this vulnerability represents a severe threat to industrial control environments, where compromised data could lead to process disruption or unauthorized system manipulation.
Remediation
Immediate Action: Upgrade all instances of FactoryTalk Analytics LogixAI to version 3.02 or later to secure the Redis configuration.
Proactive Monitoring: Review network access logs for suspicious connections originating from unauthorized segments and monitor Redis instance interactions for anomalous traffic patterns.
Compensating Controls: Implement strict network segmentation and firewall rules to restrict access to the Redis service to authorized hosts only, effectively isolating the service from untrusted network segments.
Exploitation status
Public Exploit Available: Unknown.
Analyst recommendation
The severity of this vulnerability necessitates immediate attention to prevent unauthorized access to sensitive operational data. Administrators should prioritize upgrading to version 3.02 to ensure the Redis instance is properly secured and the attack vector is closed. While internal network access is required for exploitation, the potential for total impact on data integrity makes rapid remediation essential.