CVE-2025-14376
Unknown
Unknown - Not Provided
Plaintext Secret Exposure in Verve Asset Manager ADI Server
Publication date: 2026-01-20
Last updated on: 2026-01-20
Assigner: Rockwell Automation
Description
Description
A security issue was discovered within the legacy ADI server component of Verve Asset Manager, caused by plaintext secrets stored in environment variables on the ADI server. This component has been retired and has been optional since the 1.36 release in 2024.
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| verve | asset_manager | to 1.36 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-922 | The product stores sensitive information without properly limiting read or write access by unauthorized actors. |