Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareNov 21, 2024 May 11, 2023 N/A· v4 6.5 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify s...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareNov 21, 2024 May 11, 2023 N/A· v4 6.1 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more |
1Rockwellautomation 2Armorstart St 281e Firmware Armorstart St 284ee FirmwareJan 24, 2025 May 11, 2023 N/A· v4 5.9 MEDIUM· v3 N/A· v2 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more |
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more |
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more |
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server Kepserver EnterpriseKepware Kepserverex+5 moreFeb 18, 2025 Mar 29, 2023 N/A· v4 9.1 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more |
4Ge PtcRockwellautomation+1 more8Industrial Gateway Server Kepserver EnterpriseKepware Kepserverex+5 moreFeb 18, 2025 Mar 29, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2 This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more |
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer. An unauthentica...Show more |
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitr...Show more |
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrar...Show more |
1Rockwellautomation 1Modbus Tcp Server Add On Instructions Nov 21, 2024 Mar 17, 2023 N/A· v4 4.3 MEDIUM· v3 N/A· v2 Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last...Show more |
3Ge PtcRockwellautomation9Digital Industrial Gateway Server Kepserver EnterpriseKepware Server+6 moreNov 21, 2024 Feb 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
|
3Ge PtcRockwellautomation9Digital Industrial Gateway Server Kepserver EnterpriseKepware Server+6 moreNov 21, 2024 Feb 23, 2023 N/A· v4 9.8 CRITICAL· v3 N/A· v2
The affected products are vulnerable to an integer
overflow or wraparound, which could allow an attacker to crash the server and remotely
execute arbitrary code.
|
1Rockwellautomation 1Studio 5000 Logix Emulate Nov 21, 2024 Dec 27, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software. Users are granted elevated permissions on certain product services when the software is installed. Due to this mis...Show more |
1Rockwellautomation 5Compact Guardlogix 5380 Firmware Compactlogix 5380 FirmwareCompactlogix 5480 Firmware+2 moreNov 21, 2024 Dec 19, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a maj...Show more |
1Rockwellautomation 5Micrologix 1100 Firmware Micrologix 1400 C FirmwareMicrologix 1400 A Firmware+2 moreNov 21, 2024 Dec 16, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the abi...Show more |
1Rockwellautomation 6Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+3 moreNov 21, 2024 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
|
1Rockwellautomation 2Micrologix 1100 Firmware Micrologix 1400 FirmwareNov 21, 2024 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by...Show more |
1Rockwellautomation 1Factorytalk Alarms And Events Nov 21, 2024 Oct 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port co...Show more |