Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
HIGH 8.8
CVE-2025-9364
An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result…
Factorytalk Analytics Logixai
Mitigation only
HIGH 7.5
CVE-2025-9166
A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to …
Controllogix 5580 Firmware
No fix yet
HIGH 7.3
CVE-2024-11364
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE…
Arena
Mitigation only
HIGH 7.8
CVE-2024-37365
A remote code execution vulnerability exists in the affected
product. The vulnerability allows users to save projects within the public
directory all…
Factorytalk View
Mitigation only
HIGH 7.8
CVE-2024-7847
VULNERABILITY DETAILS
Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following…
Rslogix 5
Mitigation only
HIGH 7.5
CVE-2024-9124
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavai…
Powerflex 6000t Firmware
Mitigation only
HIGH 7.5
CVE-2024-6077
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Obj…
Compactlogix 5380 Firmware
Mitigation only
HIGH 7.5
CVE-2024-45825
CVE-2024-45825 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent…
5015 U8ihft Firmware
Mitigation only
CRITICAL 9.8
CVE-2024-45823
CVE-2024-45823 IMPACT
An
authentication bypass vulnerability exists in the affected product. The
vulnerability exists due to shared secrets across…
Factorytalk Batch View
Mitigation only
HIGH 8.8
CVE-2024-7513
CVE-2024-7513 IMPACT
A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permission…
Factorytalk View
Mitigation only
HIGH 7.5
CVE-2024-40619
CVE-2024-40619 IMPACT
A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sen…
Controllogix 5580 Firmware
Mitigation only
HIGH 7.5
CVE-2024-40620
CVE-2024-40620 IMPACT
A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results i…
Pavilion8
Mitigation only
MEDIUM 5.5
CVE-2024-6326
An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this…
Factorytalk Policy Manager
Mitigation only
HIGH 7.5
CVE-2024-6089
An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapt…
5015 Aenftxt Firmware
Mitigation only
MEDIUM 6.5
CVE-2024-6325
The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad…
Factorytalk Policy Manager
Mitigation only
HIGH 8.8
CVE-2024-6435
A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions whi…
Pavilion8
Mitigation only
MEDIUM 6.5
CVE-2024-5659
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fa…
Controllogix 5580 Firmware
Mitigation only
HIGH 7.5
CVE-2024-3493
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause …
Controllogix 5580 Firmware
Mitigation only
HIGH 7.5
CVE-2024-2424
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl…
5015 Aenftxt Firmware
Mitigation only
HIGH 7.1
CVE-2024-21920
A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries…
Arena
Mitigation only
HIGH 7.5
CVE-2024-2425
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the …
Powerflex 527 Ac Drives Firmware
No fix yet
HIGH 7.5
CVE-2024-2426
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di…
Powerflex 527 Ac Drives Firmware
Mitigation only
HIGH 7.5
CVE-2024-2427
A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data…
Powerflex 527 Ac Drives Firmware
Mitigation only
HIGH 7.5
CVE-2024-21916
A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could pot…
Controllogix 5570 Controller Firmware
Mitigation only
CRITICAL 9.1
CVE-2023-29464EPSS 10%
FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa…
Factorytalk Linx
Mitigation only
HIGH 7.5
CVE-2023-2263
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing. The new ENIP connections cannot be established if im…
Kinetix 5700 Firmware
Mitigation only
CRITICAL 9.8
CVE-2023-3595
Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious us…
1756 En2f Series A Firmware
Mitigation only
HIGH 7.5
CVE-2023-3596
Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a d…
1756 En4tr Firmware
Mitigation only
CRITICAL 9.6
CVE-2023-2746
The Rockwell Automation Enhanced HIM software contains
an API that the application uses that is not protected sufficiently and uses incorrect Cross…
Enhanced Him
No fix yet
HIGH 8.8
CVE-2023-2072
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product. The vulnerable pa…
Powermonitor 1000 Firmware
Mitigation only