← Voltar para CVEs
CVE-2025-9036
N/ADescricao
A security issue in the runtime event system allows unauthenticated connections to receive a reusable API token. This token is broadcasted over a WebSocket and can be intercepted by any local client listening on the connection.
Detalhes CVE
Pontuacao CVSS v3.1N/A
Publicado8/14/2025
Ultima modificacao8/15/2025
Fontenvd
Avistamentos honeypot0
Fraquezas (CWE)
CWE-200
Referencias
https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1740.html(PSIRT@rockwellautomation.com)
Correlacoes IOC
Sem correlacoes registradas
This product uses data from the NVD API but is not endorsed or certified by the NVD.