PT-2025-46344 · Rockwell Automation · Studio 5000® Simulation Interface™

Published

2025-11-11

·

Updated

2025-11-11

·

CVE-2025-11697

CVSS v4.0

8.9

High

VectorAV:L/AC:L/AT:P/PR:N/UI:N/VC:H/VI:H/VA:H/SC:H/SI:H/SA:H
Name of the Vulnerable Software and Affected Versions Studio 5000® Simulation Interface™ (affected versions not specified)
Description A local code execution issue exists within Studio 5000® Simulation Interface™ through its API. A Windows user on the system can extract files using path traversal sequences. This can lead to the execution of scripts with Administrator privileges upon system reboot.
Recommendations At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Information Disclosure

Weakness Enumeration

Related Identifiers

CVE-2025-11697

Affected Products

Studio 5000® Simulation Interface™