Rockwellautomation
rockwellautomation
337 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (337)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspecting user may result in the use of a pointer that has not been initializ...Show more |
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200. A maliciously crafted Arena file opened by an unsuspecting user may result in the limited exposure of i...Show more |
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened by an unsuspecting user may result in the application crashing or the...Show more |
1Rockwellautomation 1Panelview 5510 Firmware Nov 21, 2024 Jul 11, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelVie...Show more |
1Rockwellautomation 4Armor Compact Guardlogix 5370 Firmware Compactlogix 5370 L1 FirmwareCompactlogix 5370 L2 Firmware+1 moreFeb 20, 2026 May 1, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. A cold restart is required for recoveri...Show more |
1Rockwellautomation 5Armor Compact Guardlogix 5370 Firmware Compact Guardlogix 5370 FirmwareCompactlogix 5370 L1 Firmware+2 moreFeb 20, 2026 May 1, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state (MNRF) in CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLo...Show more |
1Rockwellautomation 6Compactlogix 5370 L1 Firmware Compactlogix 5370 L2 FirmwareCompactlogix 5370 L3 Firmware+3 moreJun 3, 2026 Apr 25, 2019 N/A· v4 6.1 MEDIUM· v3 5.8 MEDIUM· v2 In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix...Show more |
1Rockwellautomation 1Powerflex 525 Ac Drives Firmware Nov 21, 2024 Apr 4, 2019 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. The vulnerability allows the attacker to c...Show more |
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed...Show more |
1Rockwellautomation 2Ethernet/ip Web Server Module 1756 Eweb Ethernet/ip Web Server Module 1768 EwebNov 21, 2024 Mar 27, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. A remote attacker could send a crafted UDP packet to the...Show more |
1Rockwellautomation 1Rslinx Enterprise Nov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receive...Show more |
1Rockwellautomation 3Plc5 1785 Lx Firmware RslogixSlc5/01 1747 L5x FirmwareJun 26, 2025 Mar 26, 2019 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. The potential exists for an unauthorized programming and...Show more |
1Rockwellautomation 1Rslinx Enterprise Nov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calcula...Show more |
1Rockwellautomation 1Rslinx Enterprise Nov 21, 2024 Mar 26, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calcula...Show more |
1Rockwellautomation 1Factorytalk Services Platform Nov 21, 2024 Jan 24, 2019 N/A· v4 7.5 HIGH· v3 7.8 HIGH· v2 In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial o...Show more |
1Rockwellautomation 1Powermonitor 1000 Firmware Nov 21, 2024 Dec 26, 2018 N/A· v4 8.1 HIGH· v3 6.8 MEDIUM· v2 An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because access control is implemented on the client side via a disabled attribute...Show more |
1Rockwellautomation 1Powermonitor 1000 Firmware Nov 21, 2024 Dec 26, 2018 N/A· v4 6.1 MEDIUM· v3 4.3 MEDIUM· v2 Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted userâs web browser to gain access to the affected device. |
1Rockwellautomation 161756 En2f Series A Firmware 1756 En2f Series B Firmware1756 En2f Series C Firmware+13 moreJun 3, 2026 Dec 7, 2018 N/A· v4 8.6 HIGH· v3 7.8 HIGH· v2 Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful connecti...Show more |
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop respo...Show more |
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software application to stop r...Show more |