Skip to main content

CVE-2025-7971: CWE-20: Improper Input Validation in Rockwell Automation Studio 5000 Logix Designer®

High
VulnerabilityCVE-2025-7971cvecve-2025-7971cwe-20
Published: Thu Aug 14 2025 (08/14/2025, 15:02:05 UTC)
Source: CVE Database V5
Vendor/Project: Rockwell Automation
Product: Studio 5000 Logix Designer®

Description

A security issues exists within Studio 5000 Logix Designer due to unsafe handling of environment variables. If the specified path lacks a valid file, Logix Designer crashes; However, it may be possible to execute malicious code without triggering a crash.

Technical Details

Data Version
5.1
Assigner Short Name
Rockwell
Date Reserved
2025-07-21T19:15:30.931Z
Cvss Version
4.0
State
PUBLISHED

Threat ID: 689dfe47ad5a09ad005bef48

Added to database: 8/14/2025, 3:18:31 PM

Last updated: 8/14/2025, 3:18:31 PM

Views: 1

Actions

Please log in to the Console to use AI analysis features.

Need enhanced features?

Contact root@offseq.com for Pro access with improved analysis and higher rate limits.

Latest Threats