CVE-2025-14377
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
Scoring
- Severity
- HIGH
- CVSS base score
- 8.8
- CVSS vector
- CVSS:4.0/AV:N/AC:L/AT:P/PR:H/UI:N/VC:H/VI:H/VA:L/SC:H/SI:H/SA:H
- EPSS probability
- 0.18%
- CWE
- CWE-312
- Published
- 2026-01-20
- Last modified
- 2026-03-12
Affected products
- Rockwell Automation Verve Asset Manager
Weakness type
Related vulnerabilities
- CVE-2026-80058 — Dell SCG 5.0 Appliance versions prior to 5.36.00.16 and Dell SCG 5.0 Application versions prior to...
- CVE-2026-86280 — SourceCodester Syllabus-Aligned Learning Management & Examination System cict_portal.sql cleartext storage
- CVE-2026-53603 — nebula-mesh: Operator session tokens stored in plaintext in the database
- CVE-2026-83551 — Cleartext storage of HMAC signing key in Amazon SageMaker Python SDK @step/@remote pipeline path
- CVE-2026-77975 — Ebyte NA111-M Cleartext Storage of Sensitive Information
- CVE-2026-82699 — sambitraj Student Management System Password aca.sql cleartext storage
- CVE-2026-82640 — browser-use web-ui 2.0.0 through 3.0.0 Cleartext API Key Storage
- CVE-2026-77970 — Sensitive fields nested in embedded values are not redacted in AshPaperTrail versions