Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Factorytalk View HIGH 7.8
CVE-2020-14481

The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user …

Fix: after 9.0
Fix from $1,950 2022-02-24
Factorytalk Services Platform HIGH 7.1
CVE-2020-14478

A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote conten…

Fix: after 6.11.00
Fix from $1,950 2022-02-24
1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware MEDIUM 6.1
CVE-2020-14502

The web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicious scri…

Fix: after 5.017
Fix from $1,600 2022-02-24
Factorytalk View MEDIUM 5.5
CVE-2020-14480

Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain cred…

Fix: after 9.0
Fix from $1,600 2022-02-24
1734 Aentr Point I\/o Dual Port Network Adaptor Series B Firmware MEDIUM 5.3
CVE-2020-14504

The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests. A remote, unauthenticated attacker can sen…

Fix: after 5.017
Fix from $1,600 2022-02-24
Micrologix 1100 Firmware HIGH 8.6
CVE-2021-33012

Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to f…

Mitigation only
Fix from $1,950 2021-07-09
Micro800 Firmware HIGH 7.5
CVE-2021-32926

When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the leg…

Mitigation only
Fix from $1,950 2021-06-03
Micrologix 1400 Firmware HIGH 8.6
CVE-2021-22659

Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allo…

Fix: after 21.6
Fix from $1,950 2021-03-25
Factorytalk Services Platform CRITICAL 10.0
CVE-2020-14516

In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing a…

Mitigation only
Fix from $2,300 2021-03-18
Drivetools Add On Profiles HIGH 7.8
CVE-2021-22665

Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited priv…

Fix: after 5.13
Fix from $1,950 2021-03-18
Factorytalk Services Platform CRITICAL 9.8
CVE-2021-22681 KEVEPSS 61%

Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers a…

Fix: after 20
Fix from $2,300 2021-03-03
Flex Io 1794 Aent\/b Firmware HIGH 7.5
CVE-2020-6088

An exploitable denial of service vulnerability exists in the ENIP Request Path Network Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0…

No fix yet
Fix from $1,950 2021-02-04
Rslinx HIGH 7.5
CVE-2020-13573

A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A speci…

No fix yet
Fix from $1,950 2021-01-07
Factorytalk Linx HIGH 7.5
CVE-2020-5801EPSS 25%

An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::Hand…

Fix: after 6.11
Fix from $1,950 2020-12-29
Factorytalk Linx HIGH 7.5
CVE-2020-5802EPSS 39%

An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems mes…

Fix: after 6.11
Fix from $1,950 2020-12-29
Factorytalk Diagnostics HIGH 7.5
CVE-2020-5807EPSS 34%

An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. …

Fix: after 6.11
Fix from $1,950 2020-12-29
Factorytalk Linx MEDIUM 5.5
CVE-2020-5806

An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messa…

Fix: after 6.11
Fix from $1,600 2020-12-29
Micrologix 1100 B Firmware HIGH 7.5
CVE-2020-6111

An exploitable denial-of-service vulnerability exists in the IPv4 functionality of Allen-Bradley MicroLogix 1100 Programmable Logic Controller System…

Mitigation only
Fix from $1,950 2020-12-03
Factorytalk Linx CRITICAL 9.8
CVE-2020-27251EPSS 5%

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacke…

Fix: after 6.11
Fix from $2,300 2020-11-26
Factorytalk Linx HIGH 7.5
CVE-2020-27253

A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticat…

Fix: after 6.11
Fix from $1,950 2020-11-26
Factorytalk Linx HIGH 7.5
CVE-2020-27255

A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacke…

Fix: after 6.11
Fix from $1,950 2020-11-26
Flex I\/o 1794 Aent HIGH 7.5
CVE-2020-6084

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0…

No fix yet
Fix from $1,950 2020-10-19
Flex I\/o 1794 Aent HIGH 7.5
CVE-2020-6085

An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.0…

No fix yet
Fix from $1,950 2020-10-19
Allen Bradley Flex Io 1794 Aent\/b Firmware HIGH 7.5
CVE-2020-6083

An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A spe…

No fix yet
Fix from $1,950 2020-10-14
Flex I\/o 1794 Aent\/b Firmware HIGH 7.5
CVE-2020-6086

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A spe…

No fix yet
Fix from $1,950 2020-10-14
Flex I\/o 1794 Aent\/b Firmware HIGH 7.5
CVE-2020-6087

An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. A spe…

No fix yet
Fix from $1,950 2020-10-14
Factorytalk View HIGH 8.1
CVE-2020-12028EPSS 53%

In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the re…

No fix yet
Fix from $1,950 2020-07-20
Factorytalk View HIGH 7.8
CVE-2020-12031

In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker m…

Mitigation only
Fix from $1,950 2020-07-20
Factorytalk View HIGH 7.8
CVE-2020-12029EPSS 47%

All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be…

No fix yet
Fix from $1,950 2020-07-20
Factorytalk Services Platform HIGH 8.8
CVE-2020-12033

In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers…

Mitigation only
Fix from $1,950 2020-06-23