Rockwellautomation
rockwellautomation
341 CVEs • 468 products
Products (468)
Click to collapseToggle
Products (468)
Click to collapse
CVEs (341)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Rockwellautomation 1Pavilion8 Jun 17, 2026 Aug 14, 2024 5.3 MEDIUM· v4 7.5 HIGH· v3 N/A· v2 CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results in data being sent between the Console and the Dashboard without encrypt...Show more |
1Rockwellautomation 2Controllogix 5580 Firmware Guardlogix 5580 FirmwareJun 17, 2026 Aug 14, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent over the network to the device and results in a major nonrecoverable...Show more |
1Rockwellautomation 2Factorytalk Policy Manager Factorytalk System ServicesJun 17, 2026 Jul 16, 2024 1.8 LOW· v4 5.5 MEDIUM· v3 N/A· v2 An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporar...Show more |
1Rockwellautomation 1Factorytalk Policy Manager Jun 17, 2026 Jul 16, 2024 6.0 MEDIUM· v4 6.5 MEDIUM· v3 N/A· v2 The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwella...Show more |
1Rockwellautomation 15015 Aenftxt Firmware Jun 17, 2026 Jul 16, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapter to result in a major nonrecoverable fault. If exploited, a power cyc...Show more |
A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions which should only be available to users with administrative level privileg...Show more |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 8.7 HIGH· v4 7.5 HIGH· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation ThinServer™ and cause a denial-of-service condition on the affected device. |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManage...Show more |
1Rockwellautomation 2Thinmanager ThinserverJun 17, 2026 Jun 25, 2024 9.3 CRITICAL· v4 9.8 CRITICAL· v3 N/A· v2 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager®...Show more |
1Rockwellautomation 61756 En4 Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5380 Firmware+3 moreJun 17, 2026 Jun 14, 2024 8.3 HIGH· v4 6.5 MEDIUM· v3 N/A· v2 Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abno...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Jun 14, 2024 8.5 HIGH· v4 8.8 HIGH· v3 N/A· v2 A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system. |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Jun 14, 2024 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI projec...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 Jun 14, 2024 8.2 HIGH· v4 7.5 HIGH· v3 N/A· v2 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI pr...Show more |
1Rockwellautomation 1Factorytalk View Jun 17, 2026 May 16, 2024 8.8 HIGH· v4 9.8 CRITICAL· v3 N/A· v2 A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitim...Show more |
1Rockwellautomation 81756 En4tr Firmware Compact Guardlogix 5380 FirmwareCompactlogix 5380 Firmware+5 moreJun 17, 2026 Apr 15, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix...Show more |
1Rockwellautomation 15015 Aenftxt Firmware Jun 17, 2026 Apr 15, 2024 N/A· v4 7.5 HIGH· v3 N/A· v2 An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the avai...Show more |
A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory triggering an access viola...Show more |
A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries. This could reveal sensitive information and even cause the applica...Show more |
An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by leveraging the pointer after it is properly. Once inside...Show more |
A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the software by corrupting the memory and triggering an access viola...Show more |