← Back to CVEs
CVE-2025-9036
N/ADescription
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.
CVE Details
CVSS v3.1 ScoreN/A
Published8/14/2025
Last Modified8/15/2025
Sourcenvd
Honeypot Sightings0
Weaknesses (CWE)
CWE-200
References
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1740.html(PSIRT@rockwellautomation.com)
IOC Correlations
No correlations recorded
This product uses data from the NVD API but is not endorsed or certified by the NVD.