Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Factorytalk Policy Manager HIGH 8.2
CVE-2023-2637

Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic ke…

Mitigation only
Fix from $1,950 2023-06-13
Factorytalk Policy Manager MEDIUM 5.0
CVE-2023-2638

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorizati…

Mitigation only
Fix from $1,600 2023-06-13
Kinetix 5500 Firmware CRITICAL 9.1
CVE-2023-1834

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telne…

Mitigation only
Fix from $2,300 2023-05-11
Armorstart St 284ee Firmware HIGH 7.1
CVE-2023-29030

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,950 2023-05-11
Armorstart St 284ee Firmware HIGH 7.1
CVE-2023-29031

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,950 2023-05-11
Armorstart St 284ee Firmware MEDIUM 6.5
CVE-2023-29024

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discove…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 6.1
CVE-2023-29023

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29022

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29025

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29026

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29027

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29028

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29029

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Arena CRITICAL 9.8
CVE-2023-29460

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $2,300 2023-05-09
Arena CRITICAL 9.8
CVE-2023-29461

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $2,300 2023-05-09
Arena HIGH 8.8
CVE-2023-29462

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $1,950 2023-05-09
Compactlogix 5480 Firmware HIGH 7.5
CVE-2022-3752

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-servic…

Mitigation only
Fix from $1,950 2022-12-19
Micrologix 1100 Firmware HIGH 7.5
CVE-2022-3166

Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-…

Mitigation only
Fix from $1,950 2022-12-16
Factorytalk Alarms And Events HIGH 7.5
CVE-2022-38744

An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, caus…

Mitigation only
Fix from $1,950 2022-10-27
Factorytalk Vantagepoint HIGH 8.8
CVE-2022-3158

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTal…

Mitigation only
Fix from $1,950 2022-10-17
Factorytalk Vantagepoint HIGH 8.8
CVE-2022-38743

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac…

Mitigation only
Fix from $1,950 2022-10-17
Compactlogix 1768 L43 Firmware CRITICAL 9.8
CVE-2022-1161EPSS 5%

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems…

Mitigation only
Fix from $2,300 2022-04-11
Controllogix 5580 Firmware HIGH 7.2
CVE-2022-1159

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn…

Mitigation only
Fix from $1,950 2022-04-01
Micrologix 1100 Firmware HIGH 8.6
CVE-2021-33012

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to f…

Mitigation only
Fix from $1,950 2021-07-09
Micro800 Firmware HIGH 7.5
CVE-2021-32926

When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the leg…

Mitigation only
Fix from $1,950 2021-06-03
Factorytalk Services Platform CRITICAL 10.0
CVE-2020-14516

In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing a…

Mitigation only
Fix from $2,300 2021-03-18
Flex Io 1794 Aent\/b Firmware HIGH 7.5
CVE-2020-6088

An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0…

No fix yet
Fix from $1,950 2021-02-04
Rslinx HIGH 7.5
CVE-2020-13573

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A speci…

No fix yet
Fix from $1,950 2021-01-07
Micrologix 1100 B Firmware HIGH 7.5
CVE-2020-6111

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller System…

Mitigation only
Fix from $1,950 2020-12-03
Flex I\/o 1794 Aent HIGH 7.5
CVE-2020-6084

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0…

No fix yet
Fix from $1,950 2020-10-19