CVE-2025-7353
BaseFortify
Publication date: 2025-08-14
Last updated on: 2025-08-15
Assigner: Rockwell Automation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| rockwell_automation | control_logix | 12.001 |
| rockwell_automation | control_logix | 11.004 |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-1188 | The product initializes or sets a resource with a default that is intended to be changed by the product's installer, administrator, or maintainer, but the default is not secure. |
Attack-Flow Graph
AI Powered Q&A
Can you explain this vulnerability to me?
This vulnerability exists because the web-based debugger agent on Rockwell Automation ControlLogix Ethernet Modules can be accessed remotely if a specific IP address is used. This access allows attackers to perform memory dumps, modify memory contents, and control the execution flow of the device.
How can this vulnerability impact me? :
An attacker exploiting this vulnerability can gain unauthorized control over the affected device by dumping memory, altering memory, and manipulating execution flow. This can lead to disruption of operations, unauthorized changes to system behavior, and potential compromise of the industrial control system.