← Back

Rockwellautomation

rockwellautomation

337 CVEs • 468 products

Products (468)

Click to collapse
Toggle
Arena
arena
Thinmanager
thinmanager
Rslinx
rslinx
Micrologix
micrologix
1756 Enbt
1756-enbt
1756 Eweb
1756-eweb
1768 Enbt
1768-enbt
1768 Eweb
1768-eweb
Compactlogix
compactlogix
Controllogix
controllogix
Guardlogix
guardlogix
Softlogix
softlogix
Rslogix 500
rslogix_500
Pavilion8
pavilion8
Rslogix 5000
rslogix_5000

CVEs (337)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Rockwellautomation
2Armorstart St 281e Firmware
Armorstart St 284ee Firmware
Nov 21, 2024
May 11, 2023
N/A· v4
6.5 MEDIUM· v3
N/A· v2
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify s...Show more
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. Show less
1Rockwellautomation
2Armorstart St 281e Firmware
Armorstart St 284ee Firmware
Nov 21, 2024
May 11, 2023
N/A· v4
6.1 MEDIUM· v3
N/A· v2
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User i...Show more
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for successful exploitation of this vulnerability. Show less
1Rockwellautomation
2Armorstart St 281e Firmware
Armorstart St 284ee Firmware
Jan 24, 2025
May 11, 2023
N/A· v4
5.9 MEDIUM· v3
N/A· v2
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify th...Show more
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface. Additionally, a malicious user could potentially cause interruptions to the availability of the web page. Show less
1Rockwellautomation
1Arena
Dec 17, 2024
May 9, 2023
N/A· v4
8.8 HIGH· v3
N/A· v2
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap. potentially resulting in a complete loss of confidentiality, integrity, and availability. Show less
1Rockwellautomation
1Arena
Dec 17, 2024
May 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow in the heap. potentially resulting in a complete loss of confidentiality, integrity, and availability. Show less
1Rockwellautomation
1Arena
Dec 17, 2024
May 9, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by u...Show more
An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a malicious user to commit unauthorized arbitrary code to the software by using a memory buffer overflow potentially resulting in a complete loss of confidentiality, integrity, and availability. Show less
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
Kepserver EnterpriseKepware Kepserverex+5 more
Feb 18, 2025
Mar 29, 2023
N/A· v4
9.1 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a heap-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-16486.Show less
4Ge
PtcRockwellautomation+1 more
8Industrial Gateway Server
Kepserver EnterpriseKepware Kepserverex+5 more
Feb 18, 2025
Mar 29, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists wit...Show more
This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vulnerability. The specific flaw exists within the handling of text encoding conversions. The issue results from the lack of proper validation of the length of user-supplied data prior to copying it to a stack-based buffer. An attacker can leverage this vulnerability to execute code in the context of SYSTEM. Was ZDI-CAN-18411.Show less
1Rockwellautomation
1Thinmanager
Nov 21, 2024
Mar 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthentica...Show more
In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's ThinManager ThinServer.  An unauthenticated remote attacker can exploit this vulnerability to crash ThinServer.exe due to a read access violation. Show less
1Rockwellautomation
1Thinmanager
Nov 21, 2024
Mar 22, 2023
N/A· v4
7.5 HIGH· v3
N/A· v2
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitr...Show more
In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit this vulnerability to download arbitrary files on the disk drive where ThinServer.exe is installed. Show less
1Rockwellautomation
1Thinmanager
Nov 21, 2024
Mar 22, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrar...Show more
In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where ThinServer.exe is installed. The attacker could overwrite existing executable files with attacker-controlled, malicious contents, potentially causing remote code execution. Show less
1Rockwellautomation
1Modbus Tcp Server Add On Instructions
Nov 21, 2024
Mar 17, 2023
N/A· v4
4.3 MEDIUM· v3
N/A· v2
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last...Show more
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request. If exploited, an unauthorized user could read the connected device’s Modbus TCP Server AOI information. Show less
3Ge
PtcRockwellautomation
9Digital Industrial Gateway Server
Kepserver EnterpriseKepware Server+6 more
Nov 21, 2024
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.
3Ge
PtcRockwellautomation
9Digital Industrial Gateway Server
Kepserver EnterpriseKepware Server+6 more
Nov 21, 2024
Feb 23, 2023
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.
1Rockwellautomation
1Studio 5000 Logix Emulate
Nov 21, 2024
Dec 27, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this mis...Show more
A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when the software is installed. Due to this misconfiguration, a malicious user could potentially achieve remote code execution on the targeted software. Show less
1Rockwellautomation
5Compact Guardlogix 5380 Firmware
Compactlogix 5380 FirmwareCompactlogix 5480 Firmware+2 more
Nov 21, 2024
Dec 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a maj...Show more
An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project file to bring the device back online and continue normal operation. Show less
1Rockwellautomation
5Micrologix 1100 Firmware
Micrologix 1400 C FirmwareMicrologix 1400 A Firmware+2 more
Nov 21, 2024
Dec 16, 2022
N/A· v4
6.1 MEDIUM· v3
N/A· v2
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the abi...Show more
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The vulnerability is an unauthenticated stored cross-site scripting vulnerability in the embedded webserver. The payload is transferred to the controller over SNMP and is rendered on the homepage of the embedded website. Show less
1Rockwellautomation
6Compact Guardlogix 5370 Firmware
Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+3 more
Nov 21, 2024
Dec 16, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
1Rockwellautomation
2Micrologix 1100 Firmware
Micrologix 1400 Firmware
Nov 21, 2024
Dec 16, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by...Show more
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by an attacker with network access to the affected systems by sending TCP packets to webserver and closing it abruptly which would cause a denial-of-service condition for the web server application on the device Show less
1Rockwellautomation
1Factorytalk Alarms And Events
Nov 21, 2024
Oct 27, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port co...Show more
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML. Show less