PatchSiren cyber security CVE debrief
CVE-2025-0659 Rockwell Automation CVE debrief
Rockwell Automation DataMosaix Private Cloud contains a path traversal vulnerability that can let an authenticated administrator overwrite files outside the intended directory. According to the CISA advisory, the issue affects DataEdgePlatform DataMosaix Private Cloud versions up to 7.11 and is addressed in v7.11.01. The reported impact is primarily integrity-related, including the potential to overwrite reports and user project content.
- Vendor
- Rockwell Automation
- Product
- DataEdgePlatform DataMosaix Private Cloud
- CVSS
- MEDIUM 5.5
- CISA KEV
- Not listed in stored evidence
- Original CVE published
- 2025-01-28
- Original CVE updated
- 2025-01-28
- Advisory published
- 2025-01-28
- Advisory updated
- 2025-01-28
Who should care
Rockwell Automation DataMosaix Private Cloud operators, OT/ICS administrators, and security teams responsible for industrial automation environments should prioritize this advisory, especially where administrative access is delegated or broadly available.
Technical summary
CISA’s CSAF advisory (ICSA-25-028-05) describes a path traversal issue in DataMosaix Private Cloud. By supplying a specific character sequence in the body of the vulnerable endpoint, a threat actor with admin privileges could overwrite files outside the intended directory. The affected product entry lists Rockwell Automation DataEdgePlatform DataMosaix Private Cloud <= 7.11, and Rockwell Automation states the issue is fixed in v7.11.01.
Defensive priority
Medium. The vulnerability requires admin privileges, but it enables unauthorized file overwrites in an industrial software product and is already publicly documented with a vendor fix available.
Recommended defensive actions
- Upgrade Rockwell Automation DataEdgePlatform DataMosaix Private Cloud to v7.11.01 or the newest available version.
- Restrict and review administrative access to the platform, since exploitation requires admin privileges.
- Apply Rockwell Automation’s published security best practices for industrial automation control systems.
- Use CISA’s ICS recommended practices to harden related OT/ICS environments.
- Review file-integrity and application logs for unexpected overwrites in reports or user project locations.
Evidence notes
All claims are taken from the supplied CISA CSAF advisory and vendor remediation notes. The advisory was published and modified on 2025-01-28. The supplied CVSS vector is CVSS:3.1/AV:N/AC:L/PR:H/UI:N/S:U/C:L/I:H/A:N with a CVSS score of 5.5 (Medium). No KEV listing or threat campaign is included in the provided enrichment.
Sources and references
Verified primary and authoritative sources
-
CVE-2025-0659 CVE Program record
Publisher, destination, and source semantics verified
URL: https://www.cve.org/CVERecord?id=CVE-2025-0659
CVE Program - Official CVE Program record with source-provided CVE metadata.
-
CVE-2025-0659 NVD vulnerability detail
Publisher, destination, and source semantics verified
URL: https://nvd.nist.gov/vuln/detail/CVE-2025-0659
NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.
Supplemental references
-
Source item URL
Unverified legacy reference
URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2025/icsa-25-028-05.json
cisa_csaf
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/news-events/ics-advisories/icsa-25-028-05
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/topics/industrial-control-systems
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf
Reference
-
Source reference
Unverified legacy reference
URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014
Reference
Methodology and review provenance
AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.