VYPR

Factorytalk Energrymetrix

Sign in to watch

by Rockwellautomation

CVEs (2)

CVESevRiskCVSSEPSSKEVPublishedDescription
CVE-2016-4522Cri0.649.80.01Jul 28, 2016SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
CVE-2016-4531Hig0.497.30.21Jul 28, 2016Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote attackers to obtain access by leveraging an unattended workstation.