Back to Database
Status published
High
CVE-2025-14377
Verve Asset Manager – Plaintext Storage Vulnerabilities
Vulnerability Description
A security issue was discovered within the legacy Ansible playbook component of Verve Asset Manager, caused by plaintext secrets incorrectly stored when a playbook is running. This component has been retired and has been optional since the 1.36 release in 2024.
Impact Analysis
Refer to official advisory for detailed impact metrics.
Remediation
Ensure systems are updated to the latest vendor-supplied patch levels.
THREAT MONITOR
Am I Vulnerable?
Launch our assessment wizard to check if your infrastructure is exposed to • CVE-2025-14377
Credits & Attribution
No credits recorded in the NVD database.
References
More from Rockwell Automation
View All →CVE-2025-9466
ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9465
ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9464
Rockwell Automation ArmorStart® LT - Multiple Denial-of-Service Vulnerabilities
High
8.7
CVE-2025-9437
Rockwell Automation ArmorStart® AOP Denial-of-Service Vulnerability
High
8.7
CVE-2025-9368
432ES-IG3 Series A Denial-of-Service Vulnerability
High
8.7
Affected Vendor
Rockwell Automation
View all reports →Affected Software
Verve Asset Manager
Vulnerable Versions:
1.33 1.34 1.35 1.36 1.37 1.38 1.39 1.40 1.41 1.41.1 1.41.2 1.41.3
Timeline
Official Publish:
January 20th, 2026
Last Modified:
January 20th, 2026
Added to House:
July 22nd, 2026