A path
traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character
sequence in the body of the vulnerable endpoint, it is possible to overwrite
files outside of the intended directory. A threat actor with admin privileges could
leverage this vulnerability to overwrite reports including user projects.
Metrics
Affected Vendors & Products
References
History
Tue, 28 Jan 2025 17:15:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Metrics |
ssvc
|
Tue, 28 Jan 2025 15:30:00 +0000
Type | Values Removed | Values Added |
---|---|---|
Description | A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with admin privileges could leverage this vulnerability to overwrite reports including user projects. | |
Title | Path Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private Cloud | |
Weaknesses | CWE-200 | |
References |
| |
Metrics |
cvssV4_0
|

Status: PUBLISHED
Assigner: Rockwell
Published: 2025-01-28T15:16:38.188Z
Updated: 2025-01-28T16:21:57.505Z
Reserved: 2025-01-22T21:53:30.788Z
Link: CVE-2025-0659

Updated: 2025-01-28T16:21:53.700Z

Status : Received
Published: 2025-01-28T16:15:40.360
Modified: 2025-01-28T16:15:40.360
Link: CVE-2025-0659

No data.