CVE Explorer
CVE-2025-7773
A security issue exists within the 5032 16pt Digital Configurable module’s web server. The web server’s session number increments at an interval that correlates to the last two consecutive sign in session interval, making it predictable.
Known exploited
Not asserted
Disputed
No
Stale source
No
Conflicts
1
Preserved source conflicts
No provider value was silently selected as the winner.
affected · 3 assertions
{"defaultStatus":"unaffected","product":"5032-CFGB16M12P5DR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"5032-CFGB16M12M12LDR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/2
{"defaultStatus":"unaffected","product":"5032-CFGB16M12DR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/1
Affected products and versions
3 source assertions{"defaultStatus":"unaffected","product":"5032-CFGB16M12P5DR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/0
{"defaultStatus":"unaffected","product":"5032-CFGB16M12M12LDR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/2
{"defaultStatus":"unaffected","product":"5032-CFGB16M12DR","vendor":"Rockwell Automation","versions":[{"status":"affected","version":"1.011"}]}
- cve_program_cvelist_v5affectedurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/affected/1
Provider-owned CVSS observations
1 source assertion{"metric":{"Automatable":"NOT_DEFINED","Recovery":"NOT_DEFINED","Safety":"NOT_DEFINED","attackComplexity":"LOW","attackRequirements":"NONE","attackVector":"NETWORK","baseScore":8.8,"baseSeverity":"HIGH","privilegesRequired":"NONE","providerUrgency":"NOT_DEFINED","subAvailabilityImpact":"NONE","subConfidentialityImpact":"NONE","subIntegrityImpact":"NONE","userInteraction":"NONE","valueDensity":"NOT_DEFINED","vectorString":"CVSS:4.0/AV:N/AC:L/AT:N/PR:N/UI:N/VC:L/VI:L/VA:H/SC:N/SI:N/SA:N","version":"4.0","vulnAvailabilityImpact":"HIGH","vulnConfidentialityImpact":"LOW","vulnIntegrityImpact":"LOW"…
- cve_program_cvelist_v5cvssurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/metrics/0/cvssV4_0
CWE assertions
1 source assertion{"cweId":"CWE-863","description":"CWE-863: Incorrect Authorization","lang":"en","type":"CWE"}
- cve_program_cvelist_v5cweurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/problemTypes/0/descriptions/0
Source references
1 source assertion{"url":"https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.SD1733.html"}
- cve_program_cvelist_v5referenceurn:baitaphish:normalized-source-record:v2:42d8b954ac64b7295603d12e02e7679ab911cee90c8845161cdd0ff9d2dd8341 · sha256:3b0d6d26f4654ad8… · /containers/cna/references/0
Attribution and limitations
- CVE Program CVEList V5: Reproduce the MITRE copyright designation and CVE license in copies. Source →
Provider severity values are preserved separately. Baitaphish does not convert them into a risk rating, infer affected products, or treat EPSS as observed exploitation.