CVE-2025-14376
Plaintext Secret Exposure in Verve Asset Manager ADI Server
Publication date: 2026-01-20
Last updated on: 2026-01-20
Assigner: Rockwell Automation
Description
Description
CVSS Scores
EPSS Scores
| Probability: | |
| Percentile: |
Meta Information
Affected Vendors & Products
| Vendor | Product | Version / Range |
|---|---|---|
| verve | asset_manager | to 1.36 (exc) |
Helpful Resources
Exploitability
| CWE ID | Description |
|---|---|
| CWE-922 | The product stores sensitive information without properly limiting read or write access by unauthorized actors. |
Attack-Flow Graph
AI Powered Q&A
How can this vulnerability impact me? :
The impact of this vulnerability includes potential unauthorized access to sensitive secrets stored in plaintext, which could lead to compromise of the ADI server's security, unauthorized actions, or data breaches. Since the component is legacy and optional since version 1.36, the risk depends on whether this component is in use.
Can you explain this vulnerability to me?
This vulnerability involves the legacy ADI server component of Verve Asset Manager, where plaintext secrets are stored in environment variables on the ADI server. This insecure storage of sensitive information can lead to unauthorized access or exposure of these secrets.