Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Factorytalk Vantagepoint May 14, 2025 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL s...Show more |
1Rockwellautomation 1Factorytalk Vantagepoint May 13, 2025 Oct 17, 2022 N/A· v4 8.8 HIGH· v3 N/A· v2 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user w...Show more |
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS request, causing a heap-based buffer overflow...Show more |
1Rockwellautomation 1Isagraf Workbench Nov 21, 2024 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the objects that can be deserialized. This vul...Show more |
1Rockwellautomation 1Isagraf Workbench Nov 21, 2024 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse the file system when opened by ISaGRAF W...Show more |
1Rockwellautomation 1Isagraf Workbench Nov 21, 2024 Aug 25, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF...Show more |
1Rockwellautomation 9Armor Compact Guardlogix 5370 Firmware Compact Guardlogix 5370 FirmwareCompactlogix 5370 L1 Firmware+6 moreApr 17, 2025 Jul 27, 2022 N/A· v4 8.6 HIGH· v3 N/A· v2 The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop....Show more |
1Rockwellautomation 2Micrologix 1100 Firmware Micrologix 1400 FirmwareNov 21, 2024 Jul 20, 2022 N/A· v4 6.5 MEDIUM· v3 N/A· v2 The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks. |
1Rockwellautomation 9Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5370 Firmware+6 moreNov 21, 2024 Jun 2, 2022 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target d...Show more |
1Rockwellautomation 3Connected Component Workbench Isagraf WorkbenchSafety Instrumented Systems WorkstationNov 21, 2024 May 17, 2022 N/A· v4 7.8 HIGH· v3 6.8 MEDIUM· v2 Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be des...Show more |
1Rockwellautomation 24Compact Guardlogix 5370 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 1768 L43 Firmware+21 moreNov 21, 2024 Apr 11, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a sep...Show more |
1Rockwellautomation 5Compact Guardlogix 5380 Firmware Compactlogix 5380 FirmwareCompactlogix 5480 Firmware+2 moreNov 21, 2024 Apr 1, 2022 N/A· v4 7.2 HIGH· v3 6.5 MEDIUM· v2 Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectabl...Show more |
1Rockwellautomation 3Connected Components Workbench IsagrafSafety Instrumented Systems WorkstationNov 21, 2024 Apr 1, 2022 N/A· v4 5.5 MEDIUM· v3 4.3 MEDIUM· v2 When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this t...Show more |
1Rockwellautomation 1Factorytalk Services Platform Apr 17, 2025 Apr 1, 2022 N/A· v4 8.8 HIGH· v3 6.0 MEDIUM· v2 Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in R...Show more |
1Rockwellautomation 1Connected Components Workbench Nov 21, 2024 Mar 23, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensiti...Show more |
1Rockwellautomation 1Connected Components Workbench Nov 21, 2024 Mar 23, 2022 N/A· v4 8.2 HIGH· v3 6.9 MEDIUM· v2 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL state...Show more |
1Rockwellautomation 1Connected Components Workbench Nov 21, 2024 Mar 23, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Component...Show more |