Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Controllogix 5580 Firmware HIGH 7.5
CVE-2024-6207

CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP messa…

Fix: 33.017 / 34.014+
Fix from $1,950 2024-10-14
Rslogix 5 HIGH 7.8
CVE-2024-7847

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following…

Mitigation only
Fix from $1,950 2024-10-14
Compactlogix 5380 Firmware HIGH 7.5
CVE-2024-8626

Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vul…

Fix: 33.015+
Fix from $1,950 2024-10-08
Powerflex 6000t Firmware HIGH 7.5
CVE-2024-9124

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavai…

Mitigation only
Fix from $1,950 2024-10-08
Sequencemanager MEDIUM 6.5
CVE-2024-6436

An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to…

Fix: 2.0+
Fix from $1,600 2024-09-27
Pavilion8 CRITICAL 9.8
CVE-2024-7961

A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to th…

Fix: 6.0+
Fix from $2,300 2024-09-12
Pavilion8 CRITICAL 9.1
CVE-2024-7960

The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The v…

Fix: 6.0+
Fix from $2,300 2024-09-12
2800c Optixpanel Compact Firmware HIGH 8.8
CVE-2024-8533

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permi…

Fix: 4.0.2.106 / 4.0.2.116+
Fix from $1,950 2024-09-12
Compactlogix 5380 Firmware HIGH 7.5
CVE-2024-6077

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Obj…

Mitigation only
Fix from $1,950 2024-09-12
Thinmanager HIGH 8.8
CVE-2024-45826EPSS 12%

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® process…

Fix: 13.1.3 / 13.2.2+
Fix from $1,950 2024-09-12
5015 U8ihft Firmware HIGH 7.5
CVE-2024-45825

CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent…

Mitigation only
Fix from $1,950 2024-09-12
Factorytalk Batch View CRITICAL 9.8
CVE-2024-45823

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across…

Mitigation only
Fix from $2,300 2024-09-12
Factorytalk View CRITICAL 9.8
CVE-2024-45824

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Comm…

Fix: after 14.0
Fix from $2,300 2024-09-12
Thinmanager Thinserver CRITICAL 9.8
CVE-2024-7988

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code…

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-08-26
Thinmanager Thinserver HIGH 7.8
CVE-2024-7987

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code…

Fix: 11.1.8 / 11.2.9+
Fix from $1,950 2024-08-26
Thinmanager HIGH 7.5
CVE-2024-7986

A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat acto…

Fix: 11.1.8 / 11.2.9+
Fix from $1,950 2024-08-23
Factorytalk View HIGH 8.8
CVE-2024-7513

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permission…

Mitigation only
Fix from $1,950 2024-08-14
Compactlogix 5380 Firmware HIGH 7.5
CVE-2024-7515

CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecov…

Fix: 34.014+
Fix from $1,950 2024-08-14
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-40619

CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sen…

Mitigation only
Fix from $1,950 2024-08-14
Pavilion8 HIGH 7.5
CVE-2024-40620

CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results i…

Mitigation only
Fix from $1,950 2024-08-14
Compactlogix 5380 Firmware MEDIUM 6.5
CVE-2024-7507

CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is …

Fix: 34.014+
Fix from $1,600 2024-08-14
Factorytalk Policy Manager MEDIUM 5.5
CVE-2024-6326

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this…

Mitigation only
Fix from $1,600 2024-07-16
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-6089

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapt…

Mitigation only
Fix from $1,950 2024-07-16
Factorytalk Policy Manager MEDIUM 6.5
CVE-2024-6325

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad…

Mitigation only
Fix from $1,600 2024-07-16
Pavilion8 HIGH 8.8
CVE-2024-6435

A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions whi…

Mitigation only
Fix from $1,950 2024-07-16
Thinmanager CRITICAL 9.8
CVE-2024-5989

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause …

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-06-25
Thinmanager HIGH 7.5
CVE-2024-5990

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin…

Fix: 11.1.8 / 11.2.9+
Fix from $1,950 2024-06-25
Thinmanager CRITICAL 9.8
CVE-2024-5988

Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a …

Fix: 11.1.8 / 11.2.9+
Fix from $2,300 2024-06-25
Factorytalk View HIGH 8.8
CVE-2024-37369

A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C…

Fix: 14.0+
Fix from $1,950 2024-06-14
Controllogix 5580 Firmware MEDIUM 6.5
CVE-2024-5659

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fa…

Mitigation only
Fix from $1,600 2024-06-14