Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

CRITICAL 9.8 CVE-2017-7903 A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Se… 1763 L16awa Series A after 16.000 Fix from $2,3002017-06-30 HIGH 8.6 CVE-2017-7901EPSS 7% A Predictable Value Range from Previous Values issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controlle… 1763 L16awa Series A after 16.000 Fix from $1,9502017-06-30 HIGH 8.6 CVE-2017-7914EPSS 7% A Missing Authorization issue was discovered in Rockwell Automation PanelView Plus 6 700-1500 6.00.04, 6.00.05, 6.00.42, 6.00-20140306, 6.10.20121012… Panelview Plus 6 700 1500 Firmware Mitigation only Fix from $1,9502017-06-14 HIGH 7.0 CVE-2017-5176 A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Compone… Connected Components Workbench after 9.01.00 Fix from $1,9502017-05-19 MEDIUM 5.9 CVE-2017-6024 A Resource Exhaustion issue was discovered in Rockwell Automation ControlLogix 5580 controllers V28.011, V28.012, and V28.013; ControlLogix 5580 cont… Compactlogix 5380 Firmware Mitigation only Fix from $1,6002017-05-06 CRITICAL 10.0 CVE-2016-9343EPSS 10% An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions … Softlogix 5800 Controller Firmware Mitigation only Fix from $2,3002017-02-13 HIGH 7.3 CVE-2016-9334 An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior version… 1763 L16awa Series A after 14.000 Fix from $1,9502017-02-13 HIGH 8.6 CVE-2016-5814 Buffer overflow in Rockwell Automation RSLogix Micro Starter Lite, RSLogix Micro Developer, RSLogix 500 Starter Edition, RSLogix 500 Standard Edition… Rslogix 500 Professional Edition Patch available Fix from $1,9502016-09-19 HIGH 7.3 CVE-2016-5645EPSS 30% Rockwell Automation MicroLogix 1400 PLC 1766-L32BWA, 1766-L32AWA, 1766-L32BXB, 1766-L32BWAA, 1766-L32AWAA, and 1766-L32BXBA devices have a hardcoded … 1766 L32awa Mitigation only Fix from $1,9502016-08-24 HIGH 7.3 CVE-2016-4531EPSS 8% Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 does not invalidate credentials upon a logout action, which makes it easier for remote at… Factorytalk Energrymetrix after 2.10.00 Fix from $1,9502016-07-28 CRITICAL 9.8 CVE-2016-4522EPSS 6% SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands … Factorytalk Energrymetrix after 2.10.00 Fix from $2,3002016-07-28 MEDIUM 6.3 CVE-2016-2277 IAB.exe in Rockwell Automation Integrated Architecture Builder (IAB) before 9.6.0.8 and 9.7.x before 9.7.0.2 allows remote attackers to execute arbit… Integrated Architecture Builder after 9.6.0.7 Fix from $1,6002016-04-06 MEDIUM 6.1 CVE-2016-2279EPSS 8% Cross-site scripting (XSS) vulnerability in the web server in Rockwell Automation Allen-Bradley CompactLogix 1769-L* before 28.011+ allows remote att… Compactlogix 1769 L16er Bb1b Firmware after 27.011 Fix from $1,6002016-03-02 CRITICAL 9.8 CVE-2016-0868EPSS 7% Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers… 1763 L16awa Series A Mitigation only Fix from $2,3002016-01-28 HIGH 7.5 CVE-2015-6492 Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (m… Micrologix 1100 Firmware after 15.002 Fix from $1,9502015-10-28 CRITICAL 9.8 CVE-2015-6490EPSS 7% Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attacker… Micrologix 1100 Firmware after 15.002 Fix from $2,3002015-10-28 MEDIUM 6.5 CVE-2015-6486 SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authentic… Micrologix 1100 Firmware after 15.002 Fix from $1,6002015-10-28 MEDIUM 6.9 CVE-2014-9204 Stack-based buffer overflow in OPCTest.exe in Rockwell Automation RSLinx Classic before 3.73.00 allows remote attackers to execute arbitrary code via… Rslinx 3.73.00+ Fix from $1,6002015-05-17 MEDIUM 6.9 CVE-2014-9209 Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryT… Factorytalk Services Platform after 8.00.00 Fix from $1,6002015-03-31 HIGH 7.5 CVE-2014-5424EPSS 11% Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or p… Connected Components Workbench after 6.01.00 Fix from $1,9502014-11-14 HIGH 7.1 CVE-2014-5410 The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controll… Ab Micrologix Controller Mitigation only Fix from $1,9502014-10-03 MEDIUM 6.9 CVE-2014-0755 Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which… Rslogix 5000 Design And Configuration Software Mitigation only Fix from $1,6002014-02-05 HIGH 10.0 CVE-2012-4715EPSS 8% Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and C… Rslinx Enterprise Mitigation only Fix from $1,9502013-04-18 HIGH 7.8 CVE-2012-4713 Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-S… Factorytalk Services Platform Mitigation only Fix from $1,9502013-04-18 HIGH 7.8 CVE-2012-4714 Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9… Factorytalk Services Platform Mitigation only Fix from $1,9502013-04-18 HIGH 7.1 CVE-2012-4695 LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remo… Rslinx Enterprise Mitigation only Fix from $1,9502013-04-18 CRITICAL 9.8 CVE-2012-6437EPSS 8% The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, wheth… Controllogix Controllers after 1400 Fix from $2,3002013-01-24 HIGH 8.5 CVE-2012-6439EPSS 23% When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or… Controllogix Controllers after 1400 Fix from $1,9502013-01-24 HIGH 7.5 CVE-2012-6435EPSS 33% When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or P… Controllogix Controllers after 1400 Fix from $1,9502013-01-24 HIGH 7.5 CVE-2012-6436EPSS 27% The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP,… Controllogix Controllers after 1400 Fix from $1,9502013-01-24