PatchSiren

PatchSiren cyber security CVE debrief

CVE-2025-14377 Rockwell Automation CVE debrief

CVE-2025-14377 is a high-severity information exposure issue in Rockwell Automation Verve Asset Manager’s legacy Ansible playbook component. According to the CISA republication of the vendor advisory, sensitive information could be incorrectly stored in unencrypted form during playbook execution. Rockwell Automation states the issue was resolved in version 1.42, and that the legacy component became optional starting with version 1.36 in 2024.

Vendor
Rockwell Automation
Product
Verve Asset Manager
CVSS
HIGH 7.9
CISA KEV
Not listed in stored evidence
Original CVE published
2026-01-20
Original CVE updated
2026-01-20
Advisory published
2026-01-20
Advisory updated
2026-01-20

Who should care

Administrators, engineers, and security teams responsible for Rockwell Automation Verve Asset Manager deployments, especially environments that still use or have enabled the legacy Ansible playbook component.

Technical summary

The advisory describes a flaw in the legacy Ansible playbook component of Verve Asset Manager where sensitive data could be written to storage without encryption during playbook execution. The supplied CVSS vector indicates a high-severity issue with high privileges required and no user interaction. The vendor notes the component was retired and became optional in 1.36, and that the issue was resolved in 1.42.

Defensive priority

High for any deployment that still uses the legacy playbook component; lower if the component is not installed or not enabled, but the environment should still be verified and updated to a fixed release.

Recommended defensive actions

  • Update Rockwell Automation Verve Asset Manager to version 1.42 or the latest available release.
  • Determine whether the legacy Ansible playbook component is installed or enabled, and remove or disable it if it is not required.
  • Review playbook execution workflows to confirm sensitive information is not written in unencrypted form.
  • If sensitive data may have been exposed, assess the affected systems and follow your organization’s incident response and credential-management procedures.
  • Consult Rockwell Automation’s security advisory page or TechConnect for vendor-specific guidance.

Evidence notes

The source corpus identifies this as a CISA republication of Rockwell Automation’s advisory (ICSA-26-020-03) published on 2026-01-20. The issue is described as an unencrypted storage problem in the legacy Ansible playbook component of Verve Asset Manager. The corpus also states that the component became optional starting with version 1.36 in 2024 and that the issue was resolved in version 1.42. CVSS is provided as 7.9 (HIGH) with vector CVSS:3.1/AV:N/AC:H/PR:H/UI:N/S:C/C:H/I:H/A:L.

Sources and references

Verified primary and authoritative sources

  • CVE-2025-14377 CVE Program record

    Publisher, destination, and source semantics verified

    URL: https://www.cve.org/CVERecord?id=CVE-2025-14377

    CVE Program - Official CVE Program record with source-provided CVE metadata.

  • CVE-2025-14377 NVD vulnerability detail

    Publisher, destination, and source semantics verified

    URL: https://nvd.nist.gov/vuln/detail/CVE-2025-14377

    NIST National Vulnerability Database - Official NIST NVD detail page and source-specific vulnerability assessment.

Supplemental references

  • Source item URL

    Unverified legacy reference

    URL: https://raw.githubusercontent.com/cisagov/CSAF/develop/csaf_files/OT/white/2026/icsa-26-020-03.json

    cisa_csaf

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/news-events/ics-advisories/icsa-26-020-03

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ics/alerts/ICS-ALERT-10-301-01

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/resources-tools/resources/ics-recommended-practices

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/sites/default/files/publications/Cybersecurity_Best_Practices_for_Industrial_Control_Systems.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/topics/industrial-control-systems

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/sites/default/files/publications/emailscams0905.pdf

    Reference

  • Source reference

    Unverified legacy reference

    URL: https://www.cisa.gov/uscert/ncas/tips/ST04-014

    Reference

Methodology and review provenance

AI-assisted synthesis based on stored public vulnerability evidence. System validation, approval state, and publication status do not by themselves establish human review of this revision. PatchSiren helps prioritize defensive review and does not prove exposure or remediation on any system.