← Back

Rockwellautomation

rockwellautomation

344 CVEs • 468 products

Products (468)

Click to collapse
Toggle
Arena
arena
Thinmanager
thinmanager
Rslinx
rslinx
Micrologix
micrologix
1756 Enbt
1756-enbt
1756 Eweb
1756-eweb
1768 Enbt
1768-enbt
1768 Eweb
1768-eweb
Compactlogix
compactlogix
Controllogix
controllogix
Guardlogix
guardlogix
Softlogix
softlogix
Rslogix 500
rslogix_500
Pavilion8
pavilion8
Rslogix 5000
rslogix_5000

CVEs (344)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockwellautomation
1Studio 5000 Logix Designer
Aug 25, 2026
Jul 14, 2026
7.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are no...Show more
A code execution security issue exists within Studio 5000 Logix Designer® due to an unquoted search path in the External Tools configuration. The executable paths specified in the external tools configuration file are not properly quoted, and because these paths contain spaces, the operating system may resolve them to unintended executables placed earlier in the search order. If exploited, an attacker could plant a malicious executable in a location within the search path, resulting in arbitrary code execution with the same permissions of the user running the application.Show less
1Rockwellautomation
1Studio 5000 Logix Designer
Aug 25, 2026
Jul 14, 2026
7.3 HIGH· v4
7.5 HIGH· v3
N/A· v2
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configu...Show more
A remote code execution security issue exists within Studio 5000 Logix Designer® due to incorrect authorization on a configuration file. This can allow any authenticated user to modify the paths of external tools configured within the application. If exploited, an attacker could alter the configuration to point to a malicious executable, resulting in arbitrary code execution when any user interacts with the external tools functionality.Show less
1Rockwellautomation
1Studio 5000 Logix Designer
Aug 25, 2026
Jul 14, 2026
5.4 MEDIUM· v4
7.5 HIGH· v3
N/A· v2
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file...Show more
A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure, allowing path traversal sequences to escape the intended extraction directory. If exploited, an attacker could craft a malicious ACD project file that results in arbitrary files being written to attacker-controlled locations on the file system, potentially leading to code execution.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in a...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monito...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link Sta...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessib...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.Show less
1Rockwellautomation
1Arena
Jun 17, 2026
Nov 14, 2025
7.1 HIGH· v4
7.3 HIGH· v3
N/A· v2
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitra...Show more
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.Show less
1Rockwellautomation
1Factorytalk Linx
Jun 17, 2026
Oct 14, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initi...Show more
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.Show less
1Rockwellautomation
1Factorytalk Linx
Jun 17, 2026
Oct 14, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. Thi...Show more
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.Show less
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Oct 14, 2025
8.7 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of...Show more
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.Show less