PatchSiren cyber security CVE debrief
CVE-2025-0631 Rockwell Automation CVE debrief
Rockwell Automation PowerFlex 755 is affected by a credential-exposure issue in which HTTP is used and credentials can be sent in clear text. In an OT environment, that creates a straightforward confidentiality risk for anyone able to observe traffic on the network path.
- Vendor
- Rockwell Automation
- Product
- PowerFlex 755
- CVSS
- HIGH 7.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-02-25
- Original CVE updated
- 2025-02-25
- Advisory published
- 2025-02-25
- Advisory updated
- 2025-02-25
Who should care
OT/ICS administrators, Rockwell Automation customers, plant network operators, and security teams responsible for industrial automation assets should prioritize this advisory, especially where PowerFlex 755 units are reachable on shared or monitored networks.
Technical summary
CISA’s advisory for CVE-2025-0631 says the affected PowerFlex 755 version (<=16.002.279) is vulnerable because it uses HTTP, causing credentials to be transmitted in clear text. The practical risk is passive network capture of sensitive authentication data by an attacker with visibility into the traffic path.
Defensive priority
High
Recommended defensive actions
- Upgrade Rockwell Automation PowerFlex 755 to the vendor-provided fixed release v20.3.407.
- Reduce exposure of the affected device to untrusted or broadly shared networks, since the issue involves clear-text credential transit.
- Follow Rockwell Automation and CISA industrial control system security best practices to minimize interception risk.
- Review any authentication or management traffic associated with PowerFlex 755 for assumptions that may have depended on transport confidentiality.
Evidence notes
This debrief is based on the supplied CISA CSAF advisory source for ICSA-25-056-01 / CVE-2025-0631, which identifies Rockwell Automation as the vendor, PowerFlex 755 as the product, affected versions as <=16.002.279, and the issue as credential exposure caused by HTTP clear-text transmission. The same source lists Rockwell Automation’s fixed version v20.3.407 and points to CISA ICS guidance for mitigation context. Published and modified timestamps in the supplied corpus are both 2025-02-25T07:00:00.000Z.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0631 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0631
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0631 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0631
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-056-01.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-056-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.