VYPR

Vendor CVEs

Rockwellautomation

All CVEs

398 total · sorted by risk
  • CVE-2023-20198CriKEVOct 16, 2023
    risk 0.88cvss 10.0epss 1.00

    Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and adding the Software Checker. Our investigation has determined that the actors exploited two…

  • CVE-2021-22681CriKEVMar 3, 2021
    risk 0.78cvss 9.8epss 0.61

    Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580;…

  • CVE-2023-2917CriAug 17, 2023
    risk 0.72cvss 9.8epss 0.69

    The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a path traversal vulnerability exists, via the filename field, when the ThinManager processes a certain function. If exploited, an…

  • CVE-2023-27855CriMar 22, 2023
    risk 0.68cvss 9.8epss 0.13

    In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially exploit this vulnerability to upload arbitrary files to any directory on the disk drive where…

  • CVE-2019-6553CriApr 4, 2019
    risk 0.68cvss 9.8epss 0.50

    A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed size buffer, allowing an attacker to exploit a stack-based…

  • CVE-2017-14473CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14472CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14471CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14470CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14469CriApr 5, 2018
    risk 0.68cvss 10.0epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2010-2965CriAug 5, 2010
    risk 0.68cvss 9.8epss 0.58

    The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other products, allows remote attackers to read or modify arbitrary memory locations, perform function calls,…

  • CVE-2017-14468CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14467CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.36

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14466CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14464CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.37

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14463CriApr 5, 2018
    risk 0.67cvss 9.8epss 0.38

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14465CriApr 5, 2018
    risk 0.66cvss 9.8epss 0.34

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-14462CriApr 5, 2018
    risk 0.66cvss 9.8epss 0.34

    An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive…

  • CVE-2017-16740CriJan 9, 2018
    risk 0.66cvss 10.0epss 0.07

    A Buffer Overflow issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1400 Controllers, Series B and C Versions 21.002 and earlier. The stack-based buffer overflow vulnerability has been identified, which may allow remote code execution.

  • CVE-2016-9343CriFeb 13, 2017
    risk 0.66cvss 10.0epss 0.10

    An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sending malformed common industrial protocol (CIP) packet, an attacker may be able…

  • CVE-2026-10577CriJul 14, 2026
    risk 0.65cvss epss 0.00

    A security issue exists within the 1715-AENTR EtherNet/IP Adapter. The affected product exposes a network-accessible debug port that does not enforce proper privilege controls, allowing unauthenticated remote access to intrusive command-line interface (CLI) commands. If…

  • CVE-2024-10386CriOct 25, 2024
    risk 0.65cvss 9.8epss 0.19

    CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.

  • CVE-2023-2071CriSep 12, 2023
    risk 0.65cvss 9.8epss 0.11

    Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets.  The device has the functionality, through a CIP class, to…

  • CVE-2023-0755CriFeb 23, 2023
    risk 0.65cvss 9.8epss 0.12

    The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

  • CVE-2022-1161CriApr 11, 2022
    risk 0.65cvss 10.0epss 0.05

    An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an…

  • CVE-2021-27476CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and…

  • CVE-2021-27474CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.02

    Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.

  • CVE-2021-27472CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.06

    A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.

  • CVE-2021-27470CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27468CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.

  • CVE-2021-27466CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27464CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.

  • CVE-2021-27462CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.04

    A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk…

  • CVE-2021-27460CriMar 23, 2022
    risk 0.65cvss 10.0epss 0.03

    Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain…

  • CVE-2020-14516CriMar 18, 2021
    risk 0.65cvss 10.0epss 0.04

    In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.

  • CVE-2020-27265CriJan 14, 2021
    risk 0.65cvss 9.8epss 0.10

    KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server:…

  • CVE-2020-12029CriJul 20, 2020
    risk 0.65cvss 9.0epss 0.47

    All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation…

  • CVE-2020-12001CriJun 15, 2020
    risk 0.65cvss 9.8epss 0.12

    FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx…

  • CVE-2018-14829CriSep 20, 2018
    risk 0.65cvss 9.8epss 0.16

    Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential…

  • CVE-2025-9063CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.00

    An authentication bypass security issue exists within FactoryTalk View Machine Edition Web Browser ActiveX control. Exploitation of this vulnerability allows unauthorized access to the PanelView Plus 7 Series B, including access to the file system, retrieval of diagnostic…

  • CVE-2025-7328CriOct 14, 2025
    risk 0.64cvss 9.8epss 0.01

    Multiple Broken Authentication security issues exist in the affected product. The security issues are due to missing authentication checks on critical functions. These could result in potential denial-of-service, admin account takeover, or NAT rule modifications. Devices would…

  • CVE-2025-0498CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate…

  • CVE-2025-0497CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or…

  • CVE-2025-0477CriJan 30, 2025
    risk 0.64cvss 9.8epss 0.00

    An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.

  • CVE-2024-7961CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.

  • CVE-2024-45824CriSep 12, 2024
    risk 0.64cvss 9.8epss 0.01

    CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnerabilities and allows for full unauthenticated remote code execution. The link in the mitigations…

  • CVE-2024-7988CriAug 26, 2024
    risk 0.64cvss 9.8epss 0.05

    A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This vulnerability exists due to the lack of proper data input validation, which allows files to be…

  • CVE-2024-5989CriJun 25, 2024
    risk 0.64cvss 9.8epss 0.02

    Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

  • CVE-2024-5988CriJun 25, 2024
    risk 0.64cvss 9.8epss 0.03

    Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a remote code execution condition on the Rockwell Automation ThinManager® ThinServer™.

  • CVE-2024-4609CriMay 16, 2024
    risk 0.64cvss 9.8epss 0.01

    A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack…

Page 1 of 8