Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This feature is disabled by default. When the API is enabled and handling request...Show more |
1Rockwellautomation 1Kinetix 5700 Firmware Nov 21, 2024 Jul 18, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if impacted by this vulnerability, which prohibits operational capabilitie...Show more |
1Rockwellautomation 31756 En4tr Firmware 1756 En4trk Firmware1756 En4trxt FirmwareNov 21, 2024 Jul 12, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously cr...Show more |
1Rockwellautomation 121756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+9 moreNov 21, 2024 Jul 12, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious user to perform remote code execution with persistence on the target sys...Show more |
The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross-Origin Resource Sharing (CORS) settings and, as a result, is vulnerabl...Show more |
1Rockwellautomation 1Powermonitor 1000 Firmware Nov 21, 2024 Jul 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pages do not require privileges to access and can be injected with code b...Show more |
1Rockwellautomation 1Factorytalk Transaction Manager Nov 21, 2024 Jun 13, 2023 N/A· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentia...Show more |
1Rockwellautomation 2Factorytalk Policy Manager Factorytalk System ServicesNov 21, 2024 Jun 13, 2023 N/A· v4 4.7 MEDIUM· v3 N/A· v2 The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the commu...Show more |
1Rockwellautomation 2Factorytalk Policy Manager Factorytalk System ServicesNov 21, 2024 Jun 13, 2023 N/A· v4 5.0 MEDIUM· v3 N/A· v2 Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious confi...Show more |
1Rockwellautomation 2Factorytalk Policy Manager Factorytalk System ServicesNov 21, 2024 Jun 13, 2023 N/A· v4 8.2 HIGH· v3 N/A· v2 Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a lo...Show more |
1Rockwellautomation 1Factorytalk Vantagepoint Nov 21, 2024 May 11, 2023 N/A· v4 8.8 HIGH· v3 N/A· v2 A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the sa...Show more |
Rockwell Automation ThinManager product allows the use of medium strength ciphers. If the client requests an insecure cipher, a malicious actor could potentially decrypt traffic sent between the client and server API....Show more |
1Rockwellautomation 1Kinetix 5500 Firmware Nov 21, 2024 May 11, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telnet and FTP ports open by default. This could potentially allow attacke...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareNov 21, 2024 May 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareNov 21, 2024 May 11, 2023 N/A· v4 7.1 HIGH· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJan 24, 2025 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJan 24, 2025 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJan 24, 2025 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJan 24, 2025 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareNov 21, 2024 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |