Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

1763 L16awa Series A CRITICAL 9.8
CVE-2017-7903

A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Se…

Fix: after 16.000
Fix from $2,300 2017-06-30
1763 L16awa Series A HIGH 8.6
CVE-2017-7901EPSS 7%

A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controlle…

Fix: after 16.000
Fix from $1,950 2017-06-30
Panelview Plus 6 700 1500 Firmware HIGH 8.6
CVE-2017-7914EPSS 7%

A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012…

Mitigation only
Fix from $1,950 2017-06-14
Connected Components Workbench HIGH 7.0
CVE-2017-5176

A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Compone…

Fix: after 9.01.00
Fix from $1,950 2017-05-19
Compactlogix 5380 Firmware MEDIUM 5.9
CVE-2017-6024

A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 cont…

Mitigation only
Fix from $1,600 2017-05-06
Softlogix 5800 Controller Firmware CRITICAL 10.0
CVE-2016-9343EPSS 10%

An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions …

Mitigation only
Fix from $2,300 2017-02-13
1763 L16awa Series A HIGH 7.3
CVE-2016-9334

An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior version…

Fix: after 14.000
Fix from $1,950 2017-02-13
Rslogix 500 Professional Edition HIGH 8.6
CVE-2016-5814

Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition…

Patch available
Fix from $1,950 2016-09-19
1766 L32awa HIGH 7.3
CVE-2016-5645EPSS 30%

Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded …

Mitigation only
Fix from $1,950 2016-08-24
Factorytalk Energrymetrix HIGH 7.3
CVE-2016-4531EPSS 8%

Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote at…

Fix: after 2.10.00
Fix from $1,950 2016-07-28
Factorytalk Energrymetrix CRITICAL 9.8
CVE-2016-4522EPSS 6%

SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands …

Fix: after 2.10.00
Fix from $2,300 2016-07-28
Integrated Architecture Builder MEDIUM 6.3
CVE-2016-2277

IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbit…

Fix: after 9.6.0.7
Fix from $1,600 2016-04-06
Compactlogix 1769 L16er Bb1b Firmware MEDIUM 6.1
CVE-2016-2279EPSS 8%

Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote att…

Fix: after 27.011
Fix from $1,600 2016-03-02
1763 L16awa Series A CRITICAL 9.8
CVE-2016-0868EPSS 7%

Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers…

Mitigation only
Fix from $2,300 2016-01-28
Micrologix 1100 Firmware HIGH 7.5
CVE-2015-6492

Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (m…

Fix: after 15.002
Fix from $1,950 2015-10-28
Micrologix 1100 Firmware CRITICAL 9.8
CVE-2015-6490EPSS 7%

Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attacker…

Fix: after 15.002
Fix from $2,300 2015-10-28
Micrologix 1100 Firmware MEDIUM 6.5
CVE-2015-6486

SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authentic…

Fix: after 15.002
Fix from $1,600 2015-10-28
Rslinx MEDIUM 6.9
CVE-2014-9204

Stack-based buffer overflow in OPCTest.exe in Rockwell Automation RSLinx Classic before 3.73.00 allows remote attackers to execute arbitrary code via…

Fix: 3.73.00+
Fix from $1,600 2015-05-17
Factorytalk Services Platform MEDIUM 6.9
CVE-2014-9209

Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryT…

Fix: after 8.00.00
Fix from $1,600 2015-03-31
Connected Components Workbench HIGH 7.5
CVE-2014-5424EPSS 11%

Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or p…

Fix: after 6.01.00
Fix from $1,950 2014-11-14
Ab Micrologix Controller HIGH 7.1
CVE-2014-5410

The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controll…

Mitigation only
Fix from $1,950 2014-10-03
Rslogix 5000 Design And Configuration Software MEDIUM 6.9
CVE-2014-0755

Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which…

Mitigation only
Fix from $1,600 2014-02-05
Rslinx Enterprise HIGH 10.0
CVE-2012-4715EPSS 8%

Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and C…

Mitigation only
Fix from $1,950 2013-04-18
Factorytalk Services Platform HIGH 7.8
CVE-2012-4713

Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-S…

Mitigation only
Fix from $1,950 2013-04-18
Factorytalk Services Platform HIGH 7.8
CVE-2012-4714

Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9…

Mitigation only
Fix from $1,950 2013-04-18
Rslinx Enterprise HIGH 7.1
CVE-2012-4695

LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remo…

Mitigation only
Fix from $1,950 2013-04-18
Controllogix Controllers CRITICAL 9.8
CVE-2012-6437EPSS 8%

The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth…

Fix: after 1400
Fix from $2,300 2013-01-24
Controllogix Controllers HIGH 8.5
CVE-2012-6439EPSS 23%

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or…

Fix: after 1400
Fix from $1,950 2013-01-24
Controllogix Controllers HIGH 7.5
CVE-2012-6435EPSS 33%

When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P…

Fix: after 1400
Fix from $1,950 2013-01-24
Controllogix Controllers HIGH 7.5
CVE-2012-6436EPSS 27%

The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,…

Fix: after 1400
Fix from $1,950 2013-01-24