Rockwellautomation
rockwellautomation
341 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 11783 Natr Firmware Jun 17, 2026 Oct 14, 2025 9.9 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin a...Show more |
1Rockwellautomation 1Factorytalk Analytics Logixai Jun 17, 2026 Sep 9, 2025 8.7 HIGH· v4 8.8 HIGH· v3 N/A· v2 An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result in an attacker on the intranet accessing sensitive data and potential...Show more |
1Rockwellautomation 1Controllogix 5580 Firmware Jun 17, 2026 Sep 9, 2025 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to forward messages. The issue could result in a major nonrecoverable faul...Show more |
1Rockwellautomation 1Factorytalk Optix Jun 17, 2026 Sep 9, 2025 7.3 HIGH· v4 8.8 HIGH· v3 N/A· v2 A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution. |
A server-side request forgery security issue exists within Rockwell Automation ThinManager® software due to the lack of input sanitization. Authenticated attackers can exploit this vulnerability by specifying external SM...Show more |
1Rockwellautomation 51756 En2tr Series A Firmware 1756 En2tr Series B Firmware1756 En2tr Series C Firmware+2 moreJun 17, 2026 Sep 9, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash. |
1Rockwellautomation 51756 En2tr Series A Firmware 1756 En2tr Series B Firmware1756 En2tr Series C Firmware+2 moreJun 17, 2026 Sep 9, 2025 7.1 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to un...Show more |
1Rockwellautomation 1Factorytalk Activation Manager Jun 17, 2026 Sep 9, 2025 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 A security issue exists within FactoryTalk Activation Manager. An error in the implementation of cryptography within the software could allow attackers to decrypt traffic. This could result in data exposure, session hij...Show more |
1Rockwellautomation 1Factorytalk Linx Jun 17, 2026 Aug 14, 2025 8.4 HIGH· v4 9.1 CRITICAL· v3 N/A· v2 A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, an...Show more |
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a ba...Show more |
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a ba...Show more |
A memory abuse issue exists in the Rockwell Automation Arena® Simulation. A custom file can force Arena Simulation to read and write past the end of memory space. Successful use requires user action, such as opening a ba...Show more |
A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interactio...Show more |
A remote code execution security issue exists in the Rockwell Automation Arena®. A crafted DOE file can force Arena Simulation to write beyond the boundaries of an allocated object. Exploitation requires user interactio...Show more |
1Rockwellautomation 1Thinmanager Jun 17, 2026 Apr 15, 2025 8.5 HIGH· v4 5.5 MEDIUM· v3 N/A· v2 A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor co...Show more |
A privilege escalation vulnerability exists in the Rockwell Automation ThinManager. When the software starts up, files are deleted in the temporary folder causing the Access Control Entry of the directory to inherit perm...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a stack-based memory buffer overflow. The flaw is result of improper validation of user-supplied data. If exploited a threat actor can...Show more |
A local code execution vulnerability exists in the Rockwell Automation Arena® due to a threat actor being able to read outside of the allocated memory buffer. The flaw is a result of improper validation of user-supplied...Show more |