Top technology
Linux 13140
Google 12525
Microsoft 12378
Apple 6692
Oracle 6649
Adobe 6383
Ibm 6266
Cisco 5746
Debian 3919
Apache 2864
Mozilla 2857
Redhat 2581
MEDIUM 6.1
CVE-2022-46670
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400…
Micrologix 1400 Firmware
after 21.007
HIGH 7.5
CVE-2022-3157
A vulnerability exists in the Rockwell Automation controllers that allows a malformed CIP request to cause a major non-recoverable fault (MNRF) and a…
Compactlogix 5370 Firmware
after 33
HIGH 7.5
CVE-2022-3166
Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-…
Micrologix 1100 Firmware
Mitigation only
HIGH 7.5
CVE-2022-38744
An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and
Events service could open a connection, caus…
Factorytalk Alarms And Events
Mitigation only
HIGH 8.8
CVE-2022-3158
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTal…
Factorytalk Vantagepoint
Mitigation only
HIGH 8.8
CVE-2022-38743
Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The Fac…
Factorytalk Vantagepoint
Mitigation only
CRITICAL 9.8
CVE-2022-38742EPSS 22%
Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifica…
Thinmanager
after 13.0.0
HIGH 7.8
CVE-2022-2463
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exc…
Isagraf Workbench
after 6.6.9
HIGH 7.8
CVE-2022-2464
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can…
Isagraf Workbench
after 6.6.9
HIGH 7.8
CVE-2022-2465
Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF …
Isagraf Workbench
after 6.6.9
HIGH 8.6
CVE-2020-6998
The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficient…
Armor Compact Guardlogix 5370 Firmware
after 33
MEDIUM 6.5
CVE-2022-2179
The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could …
Micrologix 1100 Firmware
after 21.007
HIGH 8.6
CVE-2022-1797
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix …
Compactlogix 5380 Firmware
33.011 / 34.011+
HIGH 7.8
CVE-2022-1118EPSS 11%
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and pr…
Connected Component Workbench
after 13.00.00
CRITICAL 9.8
CVE-2022-1161EPSS 5%
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems…
Compactlogix 1768 L43 Firmware
Mitigation only
HIGH 7.2
CVE-2022-1159
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation runn…
Controllogix 5580 Firmware
Mitigation only
MEDIUM 5.5
CVE-2022-1018
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe ca…
Connected Components Workbench
after 12.0
HIGH 8.8
CVE-2021-32960
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that ma…
Factorytalk Services Platform
after 6.11.00
CRITICAL 9.8
CVE-2021-27472EPSS 6%
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which ma…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27476
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allo…
Factorytalk Assetcentre
after 10.00
HIGH 8.6
CVE-2021-27471
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malic…
Connected Components Workbench
after 12.00.00
HIGH 8.6
CVE-2021-27475
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows…
Connected Components Workbench
after 12.00.00
HIGH 8.2
CVE-2021-27473
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extra…
Connected Components Workbench
after 12.00.00
HIGH 7.5
CVE-2021-27474
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulne…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27460
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without suf…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27462
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27464
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. Thi…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27466
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifi…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27468
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vu…
Factorytalk Assetcentre
after 10.00
CRITICAL 9.8
CVE-2021-27470
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies s…
Factorytalk Assetcentre
after 10.00