Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

CVE-2025-11085— FactoryTalk® DataMosaix™ Private Cloud – Persistent XSS

EPSS 0.09% · P25
Get alerts for future matching vulnerabilitiesLog in to subscribe

I. Basic Information for CVE-2025-11085

Vulnerability Information

Have questions about the vulnerability? See if Shenlong's analysis helps!
View Shenlong Deep Dive ↗

Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.

Vulnerability Title
FactoryTalk® DataMosaix™ Private Cloud – Persistent XSS
Source: NVD (National Vulnerability Database)
Vulnerability Description
A security issue exists within DataMosaix™ Private Cloud allowing for Persistent XSS. This vulnerability can result in the execution of malicious JavaScript, allowing for account takeover, credential theft, or redirection to a malicious website.
Source: NVD (National Vulnerability Database)
CVSS Information
N/A
Source: NVD (National Vulnerability Database)
Vulnerability Type
对输出编码和转义不恰当
Source: NVD (National Vulnerability Database)
Vulnerability Title
Rockwell Automation FactoryTalk DataMosaix Private Cloud 安全漏洞
Source: CNNVD (China National Vulnerability Database)
Vulnerability Description
Rockwell Automation FactoryTalk DataMosaix Private Cloud是美国罗克韦尔(Rockwell Automation)公司的一个工业数据平台产品。 Rockwell Automation FactoryTalk DataMosaix Private Cloud存在安全漏洞,该漏洞源于允许存储型跨站脚本攻击,可能导致执行恶意JavaScript代码,进而导致账户接管、凭据窃取或重定向到恶意网站。
Source: CNNVD (China National Vulnerability Database)
CVSS Information
N/A
Source: CNNVD (China National Vulnerability Database)
Vulnerability Type
N/A
Source: CNNVD (China National Vulnerability Database)

Affected Products

VendorProductAffected VersionsCPESubscribe
Rockwell AutomationFactoryTalk® DataMosaix™ Private Cloud 7.11, 8.00 -

II. Public POCs for CVE-2025-11085

#POC DescriptionSource LinkShenlong Link
AI-Generated POCPremium

No public POC found.

Login to generate AI POC

III. Intelligence Information for CVE-2025-11085

登录查看更多情报信息。

Same Patch Batch · Rockwell Automation · 2025-11-11 · 5 CVEs total

CVE-2025-11862Verve Asset Manager Access Control Vulnerability
CVE-2025-11697Studio 5000 ® Simulation Interface Local Code Execution
CVE-2025-11696Studio 5000 ® Simulation Interface SSRF
CVE-2025-11084FactoryTalk® DataMosaix™ Private Cloud – Authentication Bypass

IV. Related Vulnerabilities

V. Comments for CVE-2025-11085

No comments yet


Leave a comment