Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

HIGH 8.2 CVE-2023-2637 Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic ke… Factorytalk Policy Manager Mitigation only Fix from $1,9502023-06-13 MEDIUM 5.0 CVE-2023-2638 Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorizati… Factorytalk Policy Manager Mitigation only Fix from $1,6002023-06-13 CRITICAL 9.1 CVE-2023-1834 Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telne… Kinetix 5500 Firmware Mitigation only Fix from $2,3002023-05-11 HIGH 7.1 CVE-2023-29030 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v… Armorstart St 284ee Firmware Mitigation only Fix from $1,9502023-05-11 HIGH 7.1 CVE-2023-29031 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v… Armorstart St 284ee Firmware Mitigation only Fix from $1,9502023-05-11 MEDIUM 6.5 CVE-2023-29024 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discove… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 6.1 CVE-2023-29023 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29022 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29025 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29026 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29027 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29028 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 MEDIUM 5.9 CVE-2023-29029 A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi… Armorstart St 284ee Firmware Mitigation only Fix from $1,6002023-05-11 CRITICAL 9.8 CVE-2023-29460 An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma… Arena Mitigation only Fix from $2,3002023-05-09 CRITICAL 9.8 CVE-2023-29461 An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma… Arena Mitigation only Fix from $2,3002023-05-09 HIGH 8.8 CVE-2023-29462 An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma… Arena Mitigation only Fix from $1,9502023-05-09 HIGH 7.5 CVE-2022-3752 An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-servic… Compactlogix 5480 Firmware Mitigation only Fix from $1,9502022-12-19 HIGH 7.5 CVE-2022-3166 Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-… Micrologix 1100 Firmware Mitigation only Fix from $1,9502022-12-16 HIGH 7.5 CVE-2022-38744 An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, caus… Factorytalk Alarms And Events Mitigation only Fix from $1,9502022-10-27 HIGH 8.8 CVE-2022-3158 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTal… Factorytalk Vantagepoint Mitigation only Fix from $1,9502022-10-17 HIGH 8.8 CVE-2022-38743 Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac… Factorytalk Vantagepoint Mitigation only Fix from $1,9502022-10-17 CRITICAL 9.8 CVE-2022-1161EPSS 5% An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems… Compactlogix 1768 L43 Firmware Mitigation only Fix from $2,3002022-04-11 HIGH 7.2 CVE-2022-1159 Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn… Controllogix 5580 Firmware Mitigation only Fix from $1,9502022-04-01 HIGH 8.6 CVE-2021-33012 Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to f… Micrologix 1100 Firmware Mitigation only Fix from $1,9502021-07-09 HIGH 7.5 CVE-2021-32926 When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the leg… Micro800 Firmware Mitigation only Fix from $1,9502021-06-03 CRITICAL 10.0 CVE-2020-14516 In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing a… Factorytalk Services Platform Mitigation only Fix from $2,3002021-03-18 HIGH 7.5 CVE-2020-6088 An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0… Flex Io 1794 Aent\/b Firmware No fix yet Fix from $1,9502021-02-04 HIGH 7.5 CVE-2020-13573 A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A speci… Rslinx No fix yet Fix from $1,9502021-01-07 HIGH 7.5 CVE-2020-6111 An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller System… Micrologix 1100 B Firmware Mitigation only Fix from $1,9502020-12-03 HIGH 7.5 CVE-2020-6084 An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0… Flex I\/o 1794 Aent No fix yet Fix from $1,9502020-10-19