Rockwellautomation
rockwellautomation
341 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 5Micrologix 1100 Firmware Micrologix 1400 C FirmwareMicrologix 1400 A Firmware+2 moreJun 17, 2026 Dec 16, 2022 N/A· v4 6.1 MEDIUM· v3 N/A· v2 Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the abi...Show more |
1Rockwellautomation 6Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+3 moreJun 17, 2026 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a denial-of-service condition (DOS).
|
1Rockwellautomation 2Micrologix 1100 Firmware Micrologix 1400 FirmwareJun 17, 2026 Dec 16, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by...Show more |
1Rockwellautomation 1Factorytalk Alarms And Events Jun 17, 2026 Oct 27, 2022 N/A· v4 7.5 HIGH· v3 N/A· v2 An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port co...Show more |
1Rockwellautomation 1Factorytalk Vantagepoint Jun 17, 2026 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL s...Show more |
1Rockwellautomation 1Factorytalk Vantagepoint Jun 17, 2026 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user w...Show more |
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow...Show more |
1Rockwellautomation 1Isagraf Workbench Jun 17, 2026 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vul...Show more |
1Rockwellautomation 1Isagraf Workbench Jun 17, 2026 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF W...Show more |
1Rockwellautomation 1Isagraf Workbench Jun 17, 2026 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF...Show more |
1Rockwellautomation 9Armor Compact Guardlogix 5370 Firmware Compact Guardlogix 5370 FirmwareCompactlogix 5370 L1 Firmware+6 moreJun 17, 2026 Jul 27, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop....Show more |
1Rockwellautomation 2Micrologix 1100 Firmware Micrologix 1400 FirmwareJun 17, 2026 Jul 20, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks. |
1Rockwellautomation 9Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+6 moreJun 17, 2026 Jun 2, 2022 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target d...Show more |
1Rockwellautomation 3Connected Component Workbench Isagraf WorkbenchSafety Instrumented Systems WorkstationJun 17, 2026 May 17, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be des...Show more |
1Rockwellautomation 24Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 1768 L43 Firmware+21 moreJun 17, 2026 Apr 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a sep...Show more |
1Rockwellautomation 5Compact Guardlogix 5380 Firmware Compactlogix 5380 FirmwareCompactlogix 5480 Firmware+2 moreJun 17, 2026 Apr 1, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectabl...Show more |
1Rockwellautomation 3Connected Components Workbench IsagrafSafety Instrumented Systems WorkstationJun 17, 2026 Apr 1, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this t...Show more |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Apr 1, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in R...Show more |
1Rockwellautomation 1Connected Components Workbench Jun 17, 2026 Mar 23, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a...Show more |