Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Factorytalk Linx CRITICAL 9.8
CVE-2020-12001EPSS 12%

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $2,300 2020-06-15
Factorytalk Linx HIGH 8.1
CVE-2020-11999

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $1,950 2020-06-15
Factorytalk Linx HIGH 7.5
CVE-2020-12003EPSS 5%

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $1,950 2020-06-15
Factorytalk Linx HIGH 7.5
CVE-2020-12005

FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH:…

Fix: after 4.11.00
Fix from $1,950 2020-06-15
Eds Subsystem HIGH 8.2
CVE-2020-12034

Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and …

Fix: after 32.0
Fix from $1,950 2020-05-20
Eds Subsystem MEDIUM 5.5
CVE-2020-12038

Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and …

Fix: after 32.0
Fix from $1,600 2020-05-19
Rslinx Classic HIGH 7.8
CVE-2020-10642

In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to th…

Fix: after 4.11.00
Fix from $1,950 2020-04-13
Factorytalk Services Platform CRITICAL 9.8
CVE-2020-6967EPSS 5%

In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics ex…

Mitigation only
Fix from $2,300 2020-03-23
Micrologix 1400 A Firmware CRITICAL 9.8
CVE-2020-6990

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…

Fix: after 21.001
Fix from $2,300 2020-03-16
Micrologix 1400 A Firmware HIGH 7.5
CVE-2020-6984

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…

Fix: after 21.001
Fix from $1,950 2020-03-16
Micrologix 1400 A Firmware HIGH 7.5
CVE-2020-6988

Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix…

Fix: after 21.001
Fix from $1,950 2020-03-16
Arena HIGH 7.8
CVE-2019-13519EPSS 6%

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may r…

Fix: after 16.00.00
Fix from $1,950 2020-01-27
Arena HIGH 7.8
CVE-2019-13521EPSS 6%

A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may r…

Fix: after 16.00.00
Fix from $1,950 2020-01-27
Arena HIGH 7.8
CVE-2019-13527EPSS 5%

In Rockwell Automation Arena Simulation Software Cat. 9502-Ax, Versions 16.00.00 and earlier, a maliciously crafted Arena file opened by an unsuspect…

Fix: after 16.00.00
Fix from $1,950 2019-09-24
Arena HIGH 7.8
CVE-2019-13510EPSS 12%

Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416. A maliciously crafted Arena file opened…

Fix: after 16.00.00
Fix from $1,950 2019-08-15
Panelview 5510 Firmware CRITICAL 9.8
CVE-2019-10970

In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a r…

Fix: 4.003 / 5.002+
Fix from $2,300 2019-07-11
Compactlogix 5370 L1 Firmware CRITICAL 9.8
CVE-2019-10952EPSS 10%

An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based…

Fix: after 30.014
Fix from $2,300 2019-05-01
Compactlogix 5370 L1 Firmware HIGH 7.5
CVE-2019-10954EPSS 6%

An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state …

Fix: after 30.014
Fix from $1,950 2019-05-01
Micrologix 1400 A Firmware MEDIUM 6.1
CVE-2019-10955

In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earli…

Fix: after 30.014
Fix from $1,600 2019-04-25
Powerflex 525 Ac Drives Firmware CRITICAL 9.8
CVE-2018-19282EPSS 6%

Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial P…

Fix: after 5.001
Fix from $2,300 2019-04-04
Rslinx CRITICAL 9.8
CVE-2019-6553EPSS 50%

A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classi…

Fix: after 4.10.00
Fix from $2,300 2019-04-04
Ethernet\/ip Web Server Module 1756 Eweb HIGH 7.5
CVE-2018-19016

Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.00…

Fix: after 5.001
Fix from $1,950 2019-03-27
Rslogix CRITICAL 9.8
CVE-2010-5305EPSS 6%

The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5…

Mitigation only
Fix from $2,300 2019-03-26
Rslinx Enterprise HIGH 7.5
CVE-2013-2805

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…

Mitigation only
Fix from $1,950 2019-03-26
Rslinx Enterprise HIGH 7.5
CVE-2013-2806

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…

Mitigation only
Fix from $1,950 2019-03-26
Rslinx Enterprise HIGH 7.5
CVE-2013-2807

Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 doe…

Mitigation only
Fix from $1,950 2019-03-26
Factorytalk Services Platform HIGH 7.5
CVE-2018-18981

In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to servi…

Fix: after 2.90
Fix from $1,950 2019-01-24
Powermonitor 1000 Firmware HIGH 8.1
CVE-2018-19616EPSS 30%

An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000. An unauthenticated user can add/edit/remove administrators because ac…

No fix yet
Fix from $1,950 2018-12-26
Powermonitor 1000 Firmware MEDIUM 6.1
CVE-2018-19615

Rockwell Automation Allen-Bradley PowerMonitor 1000 all versions. A remote attacker could inject arbitrary code into a targeted user’s web browser …

No fix yet
Fix from $1,600 2018-12-26
Micrologix 1400 Firmware HIGH 8.6
CVE-2018-17924

Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP…

Fix: after 10.10
Fix from $1,950 2018-12-07