Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Factorytalk View HIGH 7.5
CVE-2024-37368

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with…

Fix: 14.0+
Fix from $1,950 2024-06-14
Factorytalk View HIGH 7.5
CVE-2024-37367

A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system …

Fix: 14.0+
Fix from $1,950 2024-06-14
Factorytalk View CRITICAL 9.8
CVE-2024-4609

A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta…

Fix: 11.0+
Fix from $2,300 2024-05-16
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause …

Mitigation only
Fix from $1,950 2024-04-15
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-2424

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl…

Mitigation only
Fix from $1,950 2024-04-15
Arena HIGH 7.8
CVE-2024-2929

A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized co…

Fix: 16.20.03+
Fix from $1,950 2024-03-26
Arena HIGH 7.8
CVE-2024-21919

An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the…

Fix: 16.20.03+
Fix from $1,950 2024-03-26
Arena HIGH 7.1
CVE-2024-21920

A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries…

Mitigation only
Fix from $1,950 2024-03-26
Arena HIGH 7.8
CVE-2024-21912

An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the softwa…

Fix: 16.20.03+
Fix from $1,950 2024-03-26
Arena HIGH 7.8
CVE-2024-21913

A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert…

Fix: 16.20.03+
Fix from $1,950 2024-03-26
Arena HIGH 7.8
CVE-2024-21918

A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code t…

Fix: 16.20.03+
Fix from $1,950 2024-03-26
Factorytalk View MEDIUM 5.3
CVE-2024-21914

A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely wi…

Fix: 14.0+
Fix from $1,600 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2425

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the …

No fix yet
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2426

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di…

Mitigation only
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2427

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data…

Mitigation only
Fix from $1,950 2024-03-25
Factorytalk Services Platform HIGH 8.8
CVE-2024-21915

A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us…

Fix: 2.74+
Fix from $1,950 2024-02-16
Factorytalk Services Platform CRITICAL 9.1
CVE-2024-21917

A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for a…

Fix: after 6.31.00
Fix from $2,300 2024-01-31
Controllogix 5570 Controller Firmware HIGH 7.5
CVE-2024-21916

A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could pot…

Mitigation only
Fix from $1,950 2024-01-31
Factorytalk Services Platform HIGH 8.1
CVE-2023-46290

Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTal…

Fix: 2.80+
Fix from $1,950 2023-10-27
Arena HIGH 7.8
CVE-2023-27854

An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to co…

Fix: 16.20.02+
Fix from $1,950 2023-10-27
Arena HIGH 7.8
CVE-2023-27858

Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unaut…

Fix: 16.20.02+
Fix from $1,950 2023-10-27
Factorytalk View HIGH 7.5
CVE-2023-46289

Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious …

Fix: after 13.0
Fix from $1,950 2023-10-27
Factorytalk Linx CRITICAL 9.1
CVE-2023-29464EPSS 10%

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa…

Mitigation only
Fix from $2,300 2023-10-13
1756 En2t Series A Firmware CRITICAL 9.8
CVE-2023-2262

A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potential…

Fix: after 11.002
Fix from $2,300 2023-09-20
Pavilion8 MEDIUM 5.4
CVE-2023-29463

The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicio…

Fix: 5.20+
Fix from $1,600 2023-09-12
Factorytalk View CRITICAL 9.8
CVE-2023-2071EPSS 11%

Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t…

Fix: after 13.0
Fix from $2,300 2023-09-12
Thinmanager Thinserver CRITICAL 9.8
CVE-2023-2917EPSS 72%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a pat…

Fix: after 13.0.2
Fix from $2,300 2023-08-17
Thinmanager Thinserver CRITICAL 9.1
CVE-2023-2915EPSS 84%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path tr…

Fix: after 13.0.2
Fix from $2,300 2023-08-17
Thinmanager Thinserver HIGH 7.5
CVE-2023-2914EPSS 40%

The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the…

Fix: after 13.0.2
Fix from $1,950 2023-08-17
Armor Powerflex Firmware HIGH 7.5
CVE-2023-2423

A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat…

Fix: after 1.003
Fix from $1,950 2023-08-08