Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Powerflex 527 Ac Drives Firmware Jan 31, 2025 Mar 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will...Show more |
1Rockwellautomation 1Powerflex 527 Ac Drives Firmware Jan 31, 2025 Mar 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.
|
1Rockwellautomation 1Factorytalk Services Platform Dec 11, 2024 Feb 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and recei...Show more |
1Rockwellautomation 1Factorytalk Services Platform Jan 15, 2026 Jan 31, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of dig...Show more |
1Rockwellautomation 3Controllogix 5570 Controller Firmware Controllogix 5570 Redundant Controller FirmwareGuardlogix 5570 Controller FirmwareNov 21, 2024 Jan 31, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device wi...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreNov 21, 2024 Nov 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
|
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreNov 21, 2024 Nov 30, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
|
1Rockwellautomation 1Factorytalk Services Platform Nov 21, 2024 Oct 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into...Show more |
1Rockwellautomation 1Factorytalk View Nov 21, 2024 Oct 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would bec...Show more |
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the...Show more |
An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buf...Show more |
2Cisco Rockwellautomation3Allen Bradley Stratix 5200 Firmware Allen Bradley Stratix 5800 FirmwareIos XeOct 28, 2025 Oct 16, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our invest...Show more |
1Rockwellautomation 1Factorytalk Linx Nov 21, 2024 Oct 13, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage o...Show more |
1Rockwellautomation 331756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+30 moreNov 21, 2024 Sep 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. T...Show more |
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session da...Show more |
1Rockwellautomation 1Factorytalk View Nov 21, 2024 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The dev...Show more |
1Rockwellautomation 1Thinmanager Thinserver Nov 21, 2024 Aug 17, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the Thin...Show more |
1Rockwellautomation 1Thinmanager Thinserver Nov 21, 2024 Aug 17, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists when the ThinManager software processes a...Show more |
1Rockwellautomation 1Thinmanager Thinserver Nov 21, 2024 Aug 17, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products. When the ThinManager processes incoming messages, a...Show more |
1Rockwellautomation 1Armor Powerflex Firmware Nov 21, 2024 Aug 8, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat actors could exploit this vulnerability by sending an influx of netwo...Show more |