Rockwellautomation
rockwellautomation
341 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensiti...Show more |
1Rockwellautomation 1Connected Components Workbench Jun 17, 2026 Mar 23, 2022 N/A· v4 8.2 HIGH· v3 6.9 MEDIUM· v2 Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL state...Show more |
1Rockwellautomation 1Connected Components Workbench Jun 17, 2026 Mar 23, 2022 N/A· v4 8.6 HIGH· v3 6.8 MEDIUM· v2 The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Component...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arb...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthentica...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Jun 17, 2026 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnera...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable wi...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of enc...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Da...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreJun 17, 2026 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not ch...Show more |
1Rockwellautomation 21734 Aentr Point I/o Dual Port Network Adaptor Series B Firmware 1734 Aentr Point I/o Dual Port Network Adaptor Series C FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuratio...Show more |
1Rockwellautomation 21734 Aentr Point I/o Dual Port Network Adaptor Series B Firmware 1734 Aentr Point I/o Dual Port Network Adaptor Series C FirmwareJun 17, 2026 Feb 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some stri...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords....Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials. |
1Rockwellautomation 1Factorytalk Services Platform Jun 17, 2026 Feb 24, 2022 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service con...Show more |