VYPR

Vendor CVEs

Rockwellautomation

All CVEs

398 total · sorted by risk
  • CVE-2024-37365HigNov 12, 2024
    risk 0.47cvss 7.3epss 0.00

    A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access to modify and/or delete files. Additionally, a malicious user could potentially leverage this…

  • CVE-2023-2637HigJun 13, 2023
    risk 0.47cvss 7.3epss 0.00

    Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a local, authenticated non-admin user to generate an invalid…

  • CVE-2025-11743HigJan 20, 2026
    risk 0.46cvss epss 0.00

    A denial-of-service security issue in the affected product. The security issue occurs when a malformed CIP forward open message is sent. This could result in a major nonrecoverable fault a restart is required to recover.

  • CVE-2025-13823HigDec 15, 2025
    risk 0.46cvss epss 0.00

    A security issue was found in the IPv6 stack in the Micro850 and Micro870 controllers when the controllers received multiple malformed packets during fuzzing. The controllers will go into recoverable fault with fault code 0xFE60. To recover the controller, clear the fault.

  • CVE-2025-9160HigSep 9, 2025
    risk 0.46cvss epss 0.00

    A code execution security issue exists in the affected product. An attacker with physical access could abuse the maintenance menu of the controller with a crafted payload. The security issue can result in arbitrary code execution.

  • CVE-2025-24481HigJan 28, 2025
    risk 0.46cvss epss 0.00

    An Incorrect Permission Assignment Vulnerability exists in the product and version listed above. The vulnerability is due to incorrect permissions being assigned to the remote debugger port and can allow for unauthenticated access to the system configuration.

  • CVE-2025-24478HigJan 28, 2025
    risk 0.46cvss epss 0.00

    A denial-of-service vulnerability exists in the affected products. The vulnerability could allow a remote, non-privileged user to send malicious requests resulting in a major nonrecoverable fault causing a denial-of-service.

  • CVE-2025-0659HigJan 28, 2025
    risk 0.46cvss epss 0.00

    A path traversal vulnerability exists in the Rockwell Automation DataEdge Platform DataMosaix Private Cloud. By specifying the character sequence in the body of the vulnerable endpoint, it is possible to overwrite files outside of the intended directory. A threat actor with…

  • CVE-2024-3640HigMay 16, 2024
    risk 0.46cvss epss 0.00

    An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter…

  • CVE-2023-2444HigMay 11, 2023
    risk 0.46cvss 7.1epss 0.00

    A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user…

  • CVE-2023-29031HigMay 11, 2023
    risk 0.46cvss 7.0epss 0.00

    A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for…

  • CVE-2023-29030HigMay 11, 2023
    risk 0.46cvss 7.0epss 0.00

    A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for…

  • CVE-2023-29023HigMay 11, 2023
    risk 0.46cvss 7.0epss 0.00

    A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User interaction, such as a phishing attack, is required for…

  • CVE-2022-46670HigDec 16, 2022
    risk 0.46cvss 7.1epss 0.01

    Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.  The…

  • CVE-2020-14478HigFeb 24, 2022
    risk 0.46cvss 7.1epss 0.00

    A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local…

  • CVE-2017-5176HigMay 19, 2017
    risk 0.46cvss 7.0epss 0.01

    A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE,…

  • CVE-2024-45826MedSep 12, 2024
    risk 0.45cvss 6.8epss 0.12

    CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If exploited, a user can install an executable file.

  • CVE-2024-7567MedAug 13, 2024
    risk 0.45cvss epss 0.01

    A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.

  • CVE-2026-9108MedJul 14, 2026
    risk 0.44cvss epss 0.00

    A path traversal security issue exists within Studio 5000 Logix Designer® due to improper limitation of file paths within ACD project files. The software does not sanitize or validate file names embedded in the ACD file structure during the project opening procedure,…

  • CVE-2024-11158MedDec 5, 2024
    risk 0.44cvss 6.7epss 0.00

    An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable before it being initialized. If exploited, a threat actor could leverage…

  • CVE-2022-1797MedJun 2, 2022
    risk 0.44cvss 6.8epss 0.02

    A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the…

  • CVE-2020-25182MedMar 18, 2022
    risk 0.44cvss 6.7epss 0.00

    Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries. Uncontrolled loading of dynamic libraries could allow a local, unauthenticated attacker to execute arbitrary code. This vulnerability only affects ISaGRAF Runtime when…

  • CVE-2016-2279MedMar 2, 2016
    risk 0.43cvss 6.1epss 0.08

    Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.

  • CVE-2025-7330MedOct 14, 2025
    risk 0.42cvss 6.5epss 0.00

    A cross-site request forgery security issue exists in the product and version listed. The vulnerability stems from missing CSRF checks on the impacted form. This allows for unintended configuration modification if an attacker can convince a logged in admin to visit a crafted…

  • CVE-2025-8008MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.01

    A security issue exists in the protected mode of EN4TR devices, where sending specifically crafted messages during a Forward Close operation can cause the device to crash.

  • CVE-2025-8007MedSep 9, 2025
    risk 0.42cvss 6.5epss 0.00

    A security issue exists in the protected mode of 1756-EN4TR and 1756-EN2TR communication modules, where a Concurrent Forward Close operation can trigger a Major Non-Recoverable (MNFR) fault. This condition may lead to unexpected system crashes and loss of device availability.

  • CVE-2024-6436MedSep 27, 2024
    risk 0.42cvss 6.5epss 0.01

    An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to the server and cause a denial-of-service condition. If exploited, the device would become unresponsive, and a manual restart…

  • CVE-2024-7507MedAug 14, 2024
    risk 0.42cvss 6.5epss 0.01

    CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.

  • CVE-2024-6325MedJul 16, 2024
    risk 0.42cvss 6.5epss 0.00

    The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advis…

  • CVE-2024-5659MedJun 14, 2024
    risk 0.42cvss 6.5epss 0.00

    Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the…

  • CVE-2022-2179MedJul 20, 2022
    risk 0.42cvss 6.5epss 0.01

    The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.

  • CVE-2026-9307MedJun 16, 2026
    risk 0.41cvss epss 0.00

    A sensitive information disclosure security issue exists within the affected CompactLogix controllers. The controller's web server exposes CIP Connection IDs on the diagnostics webpage, which are accessible to any unauthenticated user on the network. This information can…

  • CVE-2016-2277MedApr 6, 2016
    risk 0.41cvss 6.3epss 0.01

    IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbitrary code via a crafted project file.

  • CVE-2026-9292HigJul 14, 2026
    risk 0.40cvss epss 0.00

    A Stored Cross-Site Scripting security issue exists within FactoryTalk® DataMosaix™ Private Cloud. The vulnerability stems from improper neutralization of user-supplied input within the Workflows configuration. An authenticated attacker with high privileges can inject…

  • CVE-2022-2463MedAug 25, 2022
    risk 0.40cvss 6.1epss 0.03

    Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attacker to gain the privileges of the ISaGRAF Workbench software when opened. If the software is running…

  • CVE-2021-27473MedMar 23, 2022
    risk 0.40cvss 6.1epss 0.01

    Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a…

  • CVE-2020-14502MedFeb 24, 2022
    risk 0.40cvss 6.1epss 0.01

    The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious script within the web interface that, when executed, could modify some string values on the homepage of the web interface.

  • CVE-2019-10955MedApr 25, 2019
    risk 0.40cvss 6.1epss 0.03

    In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370…

  • CVE-2018-19615MedDec 26, 2018
    risk 0.40cvss 6.1epss 0.03

    Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser to gain access to the affected device.

  • CVE-2017-6024MedMay 6, 2017
    risk 0.39cvss 5.9epss 0.03

    A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 controllers V29.011; CompactLogix 5380 controllers V28.011; and CompactLogix 5380 controllers V29.011. This vulnerability may allow an…

  • CVE-2026-9636HigJul 14, 2026
    risk 0.38cvss epss 0.00

    A security issue exists within CompactLogix® 5380, ControlLogix® 5580, and EN4 communication modules related to CIP Security certificate revocation handling. The security issue stems from the controller failing to properly reject certificates signed by an intermediate…

  • CVE-2023-2638MedJun 13, 2023
    risk 0.38cvss 5.9epss 0.00

    Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives.  This vulnerability may allow a local,…

  • CVE-2020-6998MedJul 27, 2022
    risk 0.38cvss 5.8epss 0.02

    The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop. This may allow an attacker to send specially crafted CIP…

  • CVE-2025-3618MedApr 15, 2025
    risk 0.36cvss 5.5epss 0.02

    A denial-of-service vulnerability exists in the Rockwell Automation ThinManager. The software fails to adequately verify the outcome of memory allocation while processing Type 18 messages. If exploited, a threat actor could cause a denial-of-service on the target software.

  • CVE-2024-6326MedJul 16, 2024
    risk 0.36cvss 5.5epss 0.00

    An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and…

  • CVE-2023-29024MedMay 11, 2023
    risk 0.36cvss 5.5epss 0.01

    A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discovered that could potentially allow a malicious user to view and modify sensitive data or make the web page unavailable. User…

  • CVE-2022-1018MedApr 1, 2022
    risk 0.36cvss 5.5epss 0.02

    When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this to pass data from local files to a remote web server,…

  • CVE-2020-14480MedFeb 24, 2022
    risk 0.36cvss 5.5epss 0.00

    Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.

  • CVE-2020-5806MedDec 29, 2020
    risk 0.36cvss 5.5epss 0.05

    An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All…

  • CVE-2020-12038MedMay 19, 2020
    risk 0.36cvss 5.5epss 0.03

    Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer…

Page 7 of 8