VYPR

Factorytalk

by Rockwellautomation

CVEs (7)

  • CVE-2025-7972CriAug 14, 2025
    risk 0.59cvss 9.1epss 0.01

    A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers.

  • CVE-2025-9161HigSep 9, 2025
    risk 0.57cvss 8.8epss 0.01

    A security issue exists within FactoryTalk Optix MQTT broker due to the lack of URI sanitization. This flaw enables the loading of remote Mosquito plugins, which can be used to achieve remote code execution.

  • CVE-2023-29464HigOct 13, 2023
    risk 0.54cvss 8.2epss 0.10

    FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure.…

  • CVE-2025-9068HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for…

  • CVE-2025-9067HigOct 14, 2025
    risk 0.51cvss 7.8epss 0.00

    A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with…

  • CVE-2012-0221Apr 2, 2012
    risk 0.04cvss epss 0.10

    The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service…

  • CVE-2012-0222Apr 2, 2012
    risk 0.00cvss epss 0.04

    The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.