Rockwellautomation
rockwellautomation
341 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code into the software by overstepping the memory bounda...Show more |
An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the software. This is done by writing beyond the designated memory area, which c...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Mar 25, 2024 N/A· v4 5.3 MEDIUM· v3 N/A· v2 A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it coul...Show more |
1Rockwellautomation 1Powerflex 527 Ac Drives Firmware Jun 17, 2026 Mar 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data packets are sent to the device repeatedly the device will crash and r...Show more |
1Rockwellautomation 1Powerflex 527 Ac Drives Firmware Jun 17, 2026 Mar 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a disruption in the CIP communication will occur and a manual restart will...Show more |
1Rockwellautomation 1Powerflex 527 Ac Drives Firmware Jun 17, 2026 Mar 25, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the web server will crash and need a manual restart to recover it.
|
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Feb 16, 2024 N/A· v4 8.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and recei...Show more |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Jan 31, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of dig...Show more |
1Rockwellautomation 3Controllogix 5570 Controller Firmware Controllogix 5570 Redundant Controller FirmwareGuardlogix 5570 Controller FirmwareJun 17, 2026 Jan 31, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could potentially experience a major nonrecoverable fault (MNRF). The device wi...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreJun 17, 2026 Nov 30, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2
KEPServerEX does not properly validate certificates from clients which may allow unauthenticated users to connect.
|
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server KeepserverexKepserver Enterprise+5 moreJun 17, 2026 Nov 30, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2
KEPServerEX is vulnerable to a buffer overflow which may allow an attacker to crash the product being accessed or leak information.
|
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Oct 27, 2023 N/A· v4 8.1 HIGH· v3 N/A· v2 Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Oct 27, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would bec...Show more |
Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unauthorized code to the software by using an uninitialized pointer in the...Show more |
An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buf...Show more |
2Cisco Rockwellautomation3Allen Bradley Stratix 5200 Firmware Allen Bradley Stratix 5800 FirmwareIos XeJun 17, 2026 Oct 16, 2023 N/A· v4 10.0 CRITICAL· v3 N/A· v2 Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our invest...Show more |
1Rockwellautomation 1Factorytalk Linx Jun 17, 2026 Oct 13, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage o...Show more |
1Rockwellautomation 331756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+30 moreJun 17, 2026 Sep 20, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potentially leverage this vulnerability to perform a remote code execution. T...Show more |
The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicious user could potentially retrieve other application users’ session da...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Sep 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The dev...Show more |