Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Thinmanager MEDIUM 6.5
CVE-2023-2913

An executable used in Rockwell Automation ThinManager ThinServer can be configured to enable an API feature in the HTTPS Server Settings. This featur…

Fix: after 13.0.2
Fix from $1,600 2023-07-18
Kinetix 5700 Firmware HIGH 7.5
CVE-2023-2263

The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if im…

Mitigation only
Fix from $1,950 2023-07-18
1756 En2f Series A Firmware CRITICAL 9.8
CVE-2023-3595

Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious us…

Mitigation only
Fix from $2,300 2023-07-12
1756 En4tr Firmware HIGH 7.5
CVE-2023-3596

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a d…

Mitigation only
Fix from $1,950 2023-07-12
Enhanced Him CRITICAL 9.6
CVE-2023-2746

The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross…

No fix yet
Fix from $2,300 2023-07-11
Powermonitor 1000 Firmware HIGH 8.8
CVE-2023-2072

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pa…

Mitigation only
Fix from $1,950 2023-07-11
Factorytalk Transaction Manager HIGH 7.5
CVE-2023-2778

A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a mod…

Fix: after 13.10
Fix from $1,950 2023-06-13
Factorytalk Policy Manager HIGH 8.2
CVE-2023-2637

Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic ke…

Mitigation only
Fix from $1,950 2023-06-13
Factorytalk Policy Manager MEDIUM 5.0
CVE-2023-2638

Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected.   Improper authorizati…

Mitigation only
Fix from $1,600 2023-06-13
Kinetix 5500 Firmware CRITICAL 9.1
CVE-2023-1834

Rockwell Automation was made aware that Kinetix 5500 drives, manufactured between May 2022 and January 2023, and are running v7.13 may have the telne…

Mitigation only
Fix from $2,300 2023-05-11
Factorytalk Vantagepoint HIGH 8.8
CVE-2023-2444

A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways.…

Fix: 8.40+
Fix from $1,950 2023-05-11
Thinmanager HIGH 7.5
CVE-2023-2443

Rockwell Automation ThinManager product allows the use of medium strength ciphers.  If the client requests an insecure cipher, a malicious actor coul…

Fix: after 13.0
Fix from $1,950 2023-05-11
Armorstart St 284ee Firmware HIGH 7.1
CVE-2023-29030

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,950 2023-05-11
Armorstart St 284ee Firmware HIGH 7.1
CVE-2023-29031

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,950 2023-05-11
Armorstart St 284ee Firmware MEDIUM 6.5
CVE-2023-29024

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product A cross site scripting vulnerability was discove…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 6.1
CVE-2023-29023

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user to v…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29022

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29025

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29026

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29027

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29028

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Armorstart St 284ee Firmware MEDIUM 5.9
CVE-2023-29029

A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user wi…

Mitigation only
Fix from $1,600 2023-05-11
Arena CRITICAL 9.8
CVE-2023-29460

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $2,300 2023-05-09
Arena CRITICAL 9.8
CVE-2023-29461

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $2,300 2023-05-09
Arena HIGH 8.8
CVE-2023-29462

An arbitrary code execution vulnerability contained in Rockwell Automation's Arena Simulation software was reported that could potentially allow a ma…

Mitigation only
Fix from $1,950 2023-05-09
Thinmanager HIGH 7.5
CVE-2023-27857EPSS 18%

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field …

Fix: 11.0.5 / 11.1.5+
Fix from $1,950 2023-03-22
Thinmanager CRITICAL 9.8
CVE-2023-27855EPSS 13%

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote at…

Fix: after 12.1.5
Fix from $2,300 2023-03-22
Thinmanager HIGH 7.5
CVE-2023-27856EPSS 77%

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticat…

Fix: after 12.1.5
Fix from $1,950 2023-03-22
Studio 5000 Logix Emulate HIGH 7.8
CVE-2022-3156

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on ce…

Fix: 34.00+
Fix from $1,950 2022-12-27
Compactlogix 5480 Firmware HIGH 7.5
CVE-2022-3752

An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-servic…

Mitigation only
Fix from $1,950 2022-12-19