A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.
                
            Metrics
Affected Vendors & Products
References
        History
                    Tue, 21 Oct 2025 09:45:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| First Time appeared | Rockwellautomation Rockwellautomation 1783-natr | |
| Vendors & Products | Rockwellautomation Rockwellautomation 1783-natr | 
Tue, 14 Oct 2025 14:15:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Metrics | ssvc 
 | 
Tue, 14 Oct 2025 13:00:00 +0000
| Type | Values Removed | Values Added | 
|---|---|---|
| Description | A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login. | |
| Title | Rockwell Automation Comms - 1783-NATR Stored Cross-Site Scripting Vulnerability | |
| Weaknesses | CWE-79 | |
| References |  | |
| Metrics | cvssV4_0 
 | 
 MITRE
                        MITRE
                    Status: PUBLISHED
Assigner: Rockwell
Published: 2025-10-14T12:37:44.866Z
Updated: 2025-10-14T13:18:03.602Z
Reserved: 2025-07-07T18:50:24.416Z
Link: CVE-2025-7329
 Vulnrichment
                        Vulnrichment
                    Updated: 2025-10-14T13:17:57.538Z
 NVD
                        NVD
                    Status : Awaiting Analysis
Published: 2025-10-14T13:15:39.157
Modified: 2025-10-14T19:36:29.240
Link: CVE-2025-7329
 Redhat
                        Redhat
                    No data.