Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-6207 CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP messa… Controllogix 5580 Firmware 33.017 / 34.014+ Fix from $1,9502024-10-14 HIGH 7.8 CVE-2024-7847 VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following… Rslogix 5 Mitigation only Fix from $1,9502024-10-14 HIGH 7.5 CVE-2024-8626 Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vul… Compactlogix 5380 Firmware 33.015+ Fix from $1,9502024-10-08 HIGH 7.5 CVE-2024-9124 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavai… Powerflex 6000t Firmware Mitigation only Fix from $1,9502024-10-08 MEDIUM 6.5 CVE-2024-6436 An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to… Sequencemanager 2.0+ Fix from $1,6002024-09-27 CRITICAL 9.8 CVE-2024-7961 A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to th… Pavilion8 6.0+ Fix from $2,3002024-09-12 CRITICAL 9.1 CVE-2024-7960 The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The v… Pavilion8 6.0+ Fix from $2,3002024-09-12 HIGH 8.8 CVE-2024-8533 A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permi… 2800c Optixpanel Compact Firmware 4.0.2.106 / 4.0.2.116+ Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-6077 A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Obj… Compactlogix 5380 Firmware Mitigation only Fix from $1,9502024-09-12 HIGH 8.8 CVE-2024-45826EPSS 12% CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® process… Thinmanager 13.1.3 / 13.2.2+ Fix from $1,9502024-09-12 HIGH 7.5 CVE-2024-45825 CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent… 5015 U8ihft Firmware Mitigation only Fix from $1,9502024-09-12 CRITICAL 9.8 CVE-2024-45823 CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across… Factorytalk Batch View Mitigation only Fix from $2,3002024-09-12 CRITICAL 9.8 CVE-2024-45824 CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Comm… Factorytalk View after 14.0 Fix from $2,3002024-09-12 CRITICAL 9.8 CVE-2024-7988 A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code… Thinmanager Thinserver 11.1.8 / 11.2.9+ Fix from $2,3002024-08-26 HIGH 7.8 CVE-2024-7987 A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code… Thinmanager Thinserver 11.1.8 / 11.2.9+ Fix from $1,9502024-08-26 HIGH 7.5 CVE-2024-7986 A vulnerability exists in the Rockwell Automation ThinManager® ThinServer that allows a threat actor to disclose sensitive information. A threat acto… Thinmanager 11.1.8 / 11.2.9+ Fix from $1,9502024-08-23 HIGH 8.8 CVE-2024-7513 CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permission… Factorytalk View Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-7515 CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecov… Compactlogix 5380 Firmware 34.014+ Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-40619 CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sen… Controllogix 5580 Firmware Mitigation only Fix from $1,9502024-08-14 HIGH 7.5 CVE-2024-40620 CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results i… Pavilion8 Mitigation only Fix from $1,9502024-08-14 MEDIUM 6.5 CVE-2024-7507 CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is … Compactlogix 5380 Firmware 34.014+ Fix from $1,6002024-08-14 MEDIUM 5.5 CVE-2024-6326 An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 HIGH 7.5 CVE-2024-6089 An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapt… 5015 Aenftxt Firmware Mitigation only Fix from $1,9502024-07-16 MEDIUM 6.5 CVE-2024-6325 The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad… Factorytalk Policy Manager Mitigation only Fix from $1,6002024-07-16 HIGH 8.8 CVE-2024-6435 A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions whi… Pavilion8 Mitigation only Fix from $1,9502024-07-16 CRITICAL 9.8 CVE-2024-5989 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke SQL injection into the program and cause … Thinmanager 11.1.8 / 11.2.9+ Fix from $2,3002024-06-25 HIGH 7.5 CVE-2024-5990 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to a monitor thread within Rockwell Automation Thin… Thinmanager 11.1.8 / 11.2.9+ Fix from $1,9502024-06-25 CRITICAL 9.8 CVE-2024-5988 Due to an improper input validation, an unauthenticated threat actor can send a malicious message to invoke a local or remote executable and cause a … Thinmanager 11.1.8 / 11.2.9+ Fix from $2,3002024-06-25 HIGH 8.8 CVE-2024-37369 A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access C… Factorytalk View 14.0+ Fix from $1,9502024-06-14 MEDIUM 6.5 CVE-2024-5659 Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fa… Controllogix 5580 Firmware Mitigation only Fix from $1,6002024-06-14