Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arb...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthentica...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated...Show more |
1Rockwellautomation 1Factorytalk Assetcentre Nov 21, 2024 Mar 23, 2022 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnera...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file. ISaGRAF Runtime reads the file and saves the data in a variable wi...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 6.7 MEDIUM· v3 4.6 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 6.5 MEDIUM· v3 4.3 MEDIUM· v2 Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands. The password value passed to ISaGRAF Runtime is the result of enc...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 8.8 HIGH· v3 9.3 HIGH· v2 ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP. This communication protocol provides various file system operations, as well as the uploading of applications. Da...Show more |
3Rockwellautomation Schneider ElectricXylem17Aadvance Controller Easergy C5 FirmwareEasergy T300 Firmware+14 moreNov 21, 2024 Mar 18, 2022 N/A· v4 9.8 CRITICAL· v3 9.3 HIGH· v2 Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system. Since the parameter pointing to the file name is not ch...Show more |
1Rockwellautomation 21734 Aentr Point I/o Dual Port Network Adaptor Series B Firmware 1734 Aentr Point I/o Dual Port Network Adaptor Series C FirmwareApr 17, 2025 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can send a crafted request that may allow for modification of the configuratio...Show more |
1Rockwellautomation 21734 Aentr Point I/o Dual Port Network Adaptor Series B Firmware 1734 Aentr Point I/o Dual Port Network Adaptor Series C FirmwareApr 17, 2025 Feb 24, 2022 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some stri...Show more |
1Rockwellautomation 1Factorytalk View Apr 17, 2025 Feb 24, 2022 N/A· v4 7.8 HIGH· v3 2.1 LOW· v2 The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords....Show more |
1Rockwellautomation 1Factorytalk View Apr 17, 2025 Feb 24, 2022 N/A· v4 5.5 MEDIUM· v3 2.1 LOW· v2 Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials. |
1Rockwellautomation 1Factorytalk Services Platform Apr 17, 2025 Feb 24, 2022 N/A· v4 7.1 HIGH· v3 5.6 MEDIUM· v2 A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service con...Show more |
1Rockwellautomation 1Micrologix 1100 Firmware Jun 3, 2026 Jul 9, 2021 N/A· v4 8.6 HIGH· v3 5.0 MEDIUM· v2 Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a de...Show more |
1Rockwellautomation 2Micro800 Firmware Micrologix 1400 FirmwareNov 21, 2024 Jun 3, 2021 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash. Th...Show more |
1Rockwellautomation 1Micrologix 1400 Firmware Jun 3, 2026 Mar 25, 2021 N/A· v4 8.6 HIGH· v3 7.5 HIGH· v2 Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register....Show more |
1Rockwellautomation 2Drivetools Add On Profiles Drivetools SpNov 21, 2024 Mar 18, 2021 N/A· v4 7.8 HIGH· v3 7.2 HIGH· v2 Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and com...Show more |