← Back

Rockwellautomation

rockwellautomation

341 CVEs • 468 products

Products (468)

Click to collapse
Toggle
Arena
arena
Thinmanager
thinmanager
Rslinx
rslinx
Micrologix
micrologix
1756 Enbt
1756-enbt
1756 Eweb
1756-eweb
1768 Enbt
1768-enbt
1768 Eweb
1768-eweb
Compactlogix
compactlogix
Controllogix
controllogix
Guardlogix
guardlogix
Softlogix
softlogix
Rslogix 500
rslogix_500
Pavilion8
pavilion8
Rslogix 5000
rslogix_5000

CVEs (341)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the siman.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in a...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the linker.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the expmt.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Arena
Jul 15, 2026
Jul 14, 2026
7.0 HIGH· v4
7.3 HIGH· v3
N/A· v2
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an...Show more
A security issue exists within Arena® Simulation due to a memory corruption vulnerability in the model.exe (Siman) component. The vulnerability stems from improper validation of user-supplied data, which can result in an out-of-bounds write. An attacker could leverage this vulnerability to execute arbitrary code in the context of the current process by convincing a user to open a malicious file.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP and CIP grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monito...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive grammar tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. This vulnerability is triggered during fuzzing of multiple CIP classes, which causes the CIP port to become unresponsive.
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link Sta...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limits Storms tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive limited storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles Comprehensive step limit storm tests, the device reboots
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. Fuzzing performed using Defensics causes the device to become unresponsive, requiring a reboot.
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. During execution of the Achilles EtherNet/IP Step Limit Storm tests, the device reboots unexpectedly, causing the Link State Monitor to go down for several seconds.Show less
1Rockwellautomation
1Armorstart Lt Firmware
Jun 17, 2026
Jan 20, 2026
8.7 HIGH· v4
7.5 HIGH· v3
N/A· v2
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessib...Show more
A security issue exists within ArmorStart® LT that can result in a denial-of-service condition. After running a Burp Suite active scan, the device loses ICMP connectivity, causing the web application to become inaccessible.Show less
1Rockwellautomation
1Arena
Jun 17, 2026
Nov 14, 2025
7.1 HIGH· v4
7.3 HIGH· v3
N/A· v2
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitra...Show more
Rockwell Automation Arena® suffers from a stack-based buffer overflow vulnerability. The specific flaw exists within the parsing of DOE files. Local attackers are able to exploit this issue to potentially execute arbitrary code on affected installations of Arena®. Exploiting the vulnerability requires opening a malicious DOE file.Show less
1Rockwellautomation
1Factorytalk Linx
Jun 17, 2026
Oct 14, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initi...Show more
A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.Show less
1Rockwellautomation
1Factorytalk Linx
Jun 17, 2026
Oct 14, 2025
8.5 HIGH· v4
7.8 HIGH· v3
N/A· v2
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. Thi...Show more
A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full access to all files, processes, and system resources.Show less
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Oct 14, 2025
8.7 HIGH· v4
9.1 CRITICAL· v3
N/A· v2
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of...Show more
A path traversal security issue exists within FactoryTalk View Machine Edition, allowing unauthenticated attackers on the same network as the device to delete any file within the panels operating system. Exploitation of this vulnerability is dependent on the knowledge of filenames to be deleted.Show less
1Rockwellautomation
1Factorytalk View
Jun 17, 2026
Oct 14, 2025
7.0 HIGH· v4
9.8 CRITICAL· v3
N/A· v2
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, includi...Show more
An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic information, event logs, and more.Show less
1Rockwellautomation
11783 Natr Firmware
Jun 17, 2026
Oct 14, 2025
7.0 HIGH· v4
6.5 MEDIUM· v3
N/A· v2
A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an att...Show more
A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted link.Show less
1Rockwellautomation
11783 Natr Firmware
Jun 17, 2026
Oct 14, 2025
8.5 HIGH· v4
4.8 MEDIUM· v3
N/A· v2
A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from mi...Show more
A Stored Cross-Site Scripting security issue exists in the affected product that could potentially allow a malicious user to view and modify sensitive data or make the webpage unavailable. The vulnerability stems from missing special character filtering and encoding. Successful exploitation requires an attacker to be able to update configuration fields behind admin login.Show less