Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Micrologix 1400 Firmware MEDIUM 6.1
CVE-2022-46670

Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400…

Fix: after 21.007
Fix from $1,600 2022-12-16
Compactlogix 5370 Firmware HIGH 7.5
CVE-2022-3157

A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a…

Fix: after 33
Fix from $1,950 2022-12-16
Micrologix 1100 Firmware HIGH 7.5
CVE-2022-3166

Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-…

Mitigation only
Fix from $1,950 2022-12-16
Factorytalk Alarms And Events HIGH 7.5
CVE-2022-38744

An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, caus…

Mitigation only
Fix from $1,950 2022-10-27
Factorytalk Vantagepoint HIGH 8.8
CVE-2022-3158

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTal…

Mitigation only
Fix from $1,950 2022-10-17
Factorytalk Vantagepoint HIGH 8.8
CVE-2022-38743

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac…

Mitigation only
Fix from $1,950 2022-10-17
Thinmanager CRITICAL 9.8
CVE-2022-38742EPSS 22%

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifica…

Fix: after 13.0.0
Fix from $2,300 2022-09-23
Isagraf Workbench HIGH 7.8
CVE-2022-2463

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exc…

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Isagraf Workbench HIGH 7.8
CVE-2022-2464

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can…

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Isagraf Workbench HIGH 7.8
CVE-2022-2465

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF …

Fix: after 6.6.9
Fix from $1,950 2022-08-25
Armor Compact Guardlogix 5370 Firmware HIGH 8.6
CVE-2020-6998

The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficient…

Fix: after 33
Fix from $1,950 2022-07-27
Micrologix 1100 Firmware MEDIUM 6.5
CVE-2022-2179

The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could …

Fix: after 21.007
Fix from $1,600 2022-07-20
Compactlogix 5380 Firmware HIGH 8.6
CVE-2022-1797

A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix …

Fix: 33.011 / 34.011+
Fix from $1,950 2022-06-02
Connected Component Workbench HIGH 7.8
CVE-2022-1118EPSS 11%

Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and pr…

Fix: after 13.00.00
Fix from $1,950 2022-05-17
Compactlogix 1768 L43 Firmware CRITICAL 9.8
CVE-2022-1161EPSS 5%

An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems…

Mitigation only
Fix from $2,300 2022-04-11
Controllogix 5580 Firmware HIGH 7.2
CVE-2022-1159

Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn…

Mitigation only
Fix from $1,950 2022-04-01
Connected Components Workbench MEDIUM 5.5
CVE-2022-1018

When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe ca…

Fix: after 12.0
Fix from $1,600 2022-04-01
Factorytalk Services Platform HIGH 8.8
CVE-2021-32960

Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma…

Fix: after 6.11.00
Fix from $1,950 2022-04-01
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27472EPSS 6%

A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which ma…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27476

A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allo…

Fix: after 10.00
Fix from $2,300 2022-03-23
Connected Components Workbench HIGH 8.6
CVE-2021-27471

The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malic…

Fix: after 12.00.00
Fix from $1,950 2022-03-23
Connected Components Workbench HIGH 8.6
CVE-2021-27475

Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows…

Fix: after 12.00.00
Fix from $1,950 2022-03-23
Connected Components Workbench HIGH 8.2
CVE-2021-27473

Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extra…

Fix: after 12.00.00
Fix from $1,950 2022-03-23
Factorytalk Assetcentre HIGH 7.5
CVE-2021-27474

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulne…

Fix: after 10.00
Fix from $1,950 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27460

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without suf…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27462

A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27464

The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. Thi…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27466

A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifi…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27468

The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vu…

Fix: after 10.00
Fix from $2,300 2022-03-23
Factorytalk Assetcentre CRITICAL 9.8
CVE-2021-27470

A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…

Fix: after 10.00
Fix from $2,300 2022-03-23