Vulnerability index

Browse CVEs

313 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.5 CVE-2024-37368 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with… Factorytalk View 14.0+ Fix from $1,9502024-06-14 HIGH 7.5 CVE-2024-37367 A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system … Factorytalk View 14.0+ Fix from $1,9502024-06-14 CRITICAL 9.8 CVE-2024-4609 A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL sta… Factorytalk View 11.0+ Fix from $2,3002024-05-16 HIGH 7.5 CVE-2024-3493 A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause … Controllogix 5580 Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 7.5 CVE-2024-2424 An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl… 5015 Aenftxt Firmware Mitigation only Fix from $1,9502024-04-15 HIGH 7.8 CVE-2024-2929 A memory corruption vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized co… Arena 16.20.03+ Fix from $1,9502024-03-26 HIGH 7.8 CVE-2024-21919 An uninitialized pointer in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code to the… Arena 16.20.03+ Fix from $1,9502024-03-26 HIGH 7.1 CVE-2024-21920 A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries… Arena Mitigation only Fix from $1,9502024-03-26 HIGH 7.8 CVE-2024-21912 An arbitrary code execution vulnerability in Rockwell Automation Arena Simulation could let a malicious user insert unauthorized code into the softwa… Arena 16.20.03+ Fix from $1,9502024-03-26 HIGH 7.8 CVE-2024-21913 A heap-based memory buffer overflow vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert… Arena 16.20.03+ Fix from $1,9502024-03-26 HIGH 7.8 CVE-2024-21918 A memory buffer vulnerability in Rockwell Automation Arena Simulation software could potentially allow a malicious user to insert unauthorized code t… Arena 16.20.03+ Fix from $1,9502024-03-26 MEDIUM 5.3 CVE-2024-21914 A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely wi… Factorytalk View 14.0+ Fix from $1,6002024-03-25 HIGH 7.5 CVE-2024-2425 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the … Powerflex 527 Ac Drives Firmware No fix yet Fix from $1,9502024-03-25 HIGH 7.5 CVE-2024-2426 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di… Powerflex 527 Ac Drives Firmware Mitigation only Fix from $1,9502024-03-25 HIGH 7.5 CVE-2024-2427 A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data… Powerflex 527 Ac Drives Firmware Mitigation only Fix from $1,9502024-03-25 HIGH 8.8 CVE-2024-21915 A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic us… Factorytalk Services Platform 2.74+ Fix from $1,9502024-02-16 CRITICAL 9.1 CVE-2024-21917 A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for a… Factorytalk Services Platform after 6.31.00 Fix from $2,3002024-01-31 HIGH 7.5 CVE-2024-21916 A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could pot… Controllogix 5570 Controller Firmware Mitigation only Fix from $1,9502024-01-31 HIGH 8.1 CVE-2023-46290 Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTal… Factorytalk Services Platform 2.80+ Fix from $1,9502023-10-27 HIGH 7.8 CVE-2023-27854 An arbitrary code execution vulnerability was reported to Rockwell Automation in Arena Simulation that could potentially allow a malicious user to co… Arena 16.20.02+ Fix from $1,9502023-10-27 HIGH 7.8 CVE-2023-27858 Rockwell Automation Arena Simulation contains an arbitrary code execution vulnerability that could potentially allow a malicious user to commit unaut… Arena 16.20.02+ Fix from $1,9502023-10-27 HIGH 7.5 CVE-2023-46289 Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious … Factorytalk View after 13.0 Fix from $1,9502023-10-27 CRITICAL 9.1 CVE-2023-29464EPSS 10% FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa… Factorytalk Linx Mitigation only Fix from $2,3002023-10-13 CRITICAL 9.8 CVE-2023-2262 A buffer overflow vulnerability exists in the Rockwell Automation select 1756-EN* communication devices. If exploited, a threat actor could potential… 1756 En2t Series A Firmware after 11.002 Fix from $2,3002023-09-20 MEDIUM 5.4 CVE-2023-29463 The JMX Console within the Rockwell Automation Pavilion8 is exposed to application users and does not require authentication. If exploited, a malicio… Pavilion8 5.20+ Fix from $1,6002023-09-12 CRITICAL 9.8 CVE-2023-2071EPSS 11% Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker t… Factorytalk View after 13.0 Fix from $2,3002023-09-12 CRITICAL 9.8 CVE-2023-2917EPSS 72% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability.  Due to an improper input validation, a pat… Thinmanager Thinserver after 13.0.2 Fix from $2,3002023-08-17 CRITICAL 9.1 CVE-2023-2915EPSS 84% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path tr… Thinmanager Thinserver after 13.0.2 Fix from $2,3002023-08-17 HIGH 7.5 CVE-2023-2914EPSS 40% The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the… Thinmanager Thinserver after 13.0.2 Fix from $1,9502023-08-17 HIGH 7.5 CVE-2023-2423 A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log. Threat… Armor Powerflex Firmware after 1.003 Fix from $1,9502023-08-08