Vulnerability index

Browse CVEs

94 matching
Filters 2 Clear all
Severity

Filters apply as you choose them.

Factorytalk Analytics Logixai HIGH 8.8
CVE-2025-9364

An open database issue exists in the affected product and version. The security issue stems from an over permissive Redis instance. This could result…

Mitigation only
Fix from $1,950 2025-09-09
Controllogix 5580 Firmware HIGH 7.5
CVE-2025-9166

A denial-of-service security issue exists in the affected product and version. The security issue stems from the controller repeatedly attempting to …

No fix yet
Fix from $1,950 2025-09-09
Arena HIGH 7.3
CVE-2024-11364

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE…

Mitigation only
Fix from $1,950 2024-12-19
Factorytalk View HIGH 7.8
CVE-2024-37365

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory all…

Mitigation only
Fix from $1,950 2024-11-12
Rslogix 5 HIGH 7.8
CVE-2024-7847

VULNERABILITY DETAILS Rockwell Automation used the latest versions of the CVSS scoring system to assess the following vulnerabilities. The following…

Mitigation only
Fix from $1,950 2024-10-14
Powerflex 6000t Firmware HIGH 7.5
CVE-2024-9124

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 600T. If the device is overloaded with requests, it will become unavai…

Mitigation only
Fix from $1,950 2024-10-08
Compactlogix 5380 Firmware HIGH 7.5
CVE-2024-6077

A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Obj…

Mitigation only
Fix from $1,950 2024-09-12
5015 U8ihft Firmware HIGH 7.5
CVE-2024-45825

CVE-2024-45825 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sent…

Mitigation only
Fix from $1,950 2024-09-12
Factorytalk Batch View CRITICAL 9.8
CVE-2024-45823

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across…

Mitigation only
Fix from $2,300 2024-09-12
Factorytalk View HIGH 8.8
CVE-2024-7513

CVE-2024-7513 IMPACT A code execution vulnerability exists in the affected product. The vulnerability occurs due to improper default file permission…

Mitigation only
Fix from $1,950 2024-08-14
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-40619

CVE-2024-40619 IMPACT A denial-of-service vulnerability exists in the affected products. The vulnerability occurs when a malformed CIP packet is sen…

Mitigation only
Fix from $1,950 2024-08-14
Pavilion8 HIGH 7.5
CVE-2024-40620

CVE-2024-40620 IMPACT A vulnerability exists in the affected product due to lack of encryption of sensitive information. The vulnerability results i…

Mitigation only
Fix from $1,950 2024-08-14
Factorytalk Policy Manager MEDIUM 5.5
CVE-2024-6326

An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this…

Mitigation only
Fix from $1,600 2024-07-16
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-6089

An input validation vulnerability exists in the Rockwell Automation 5015 - AENFTXT when a manipulated PTP packet is sent, causing the secondary adapt…

Mitigation only
Fix from $1,950 2024-07-16
Factorytalk Policy Manager MEDIUM 6.5
CVE-2024-6325

The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-ad…

Mitigation only
Fix from $1,600 2024-07-16
Pavilion8 HIGH 8.8
CVE-2024-6435

A privilege escalation vulnerability exists in the affected products which could allow a malicious user with basic privileges to access functions whi…

Mitigation only
Fix from $1,950 2024-07-16
Controllogix 5580 Firmware MEDIUM 6.5
CVE-2024-5659

Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fa…

Mitigation only
Fix from $1,600 2024-06-14
Controllogix 5580 Firmware HIGH 7.5
CVE-2024-3493

A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause …

Mitigation only
Fix from $1,950 2024-04-15
5015 Aenftxt Firmware HIGH 7.5
CVE-2024-2424

An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverabl…

Mitigation only
Fix from $1,950 2024-04-15
Arena HIGH 7.1
CVE-2024-21920

A memory buffer vulnerability in Rockwell Automation Arena Simulation could potentially let a threat actor read beyond the intended memory boundaries…

Mitigation only
Fix from $1,950 2024-03-26
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2425

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, the …

No fix yet
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2426

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper input validation in the device. If exploited, a di…

Mitigation only
Fix from $1,950 2024-03-25
Powerflex 527 Ac Drives Firmware HIGH 7.5
CVE-2024-2427

A denial-of-service vulnerability exists in the Rockwell Automation PowerFlex® 527 due to improper traffic throttling in the device. If multiple data…

Mitigation only
Fix from $1,950 2024-03-25
Controllogix 5570 Controller Firmware HIGH 7.5
CVE-2024-21916

A denial-of-service vulnerability exists in specific Rockwell Automation ControlLogix ang GuardLogix controllers. If exploited, the product could pot…

Mitigation only
Fix from $1,950 2024-01-31
Factorytalk Linx CRITICAL 9.1
CVE-2023-29464EPSS 10%

FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious pa…

Mitigation only
Fix from $2,300 2023-10-13
Kinetix 5700 Firmware HIGH 7.5
CVE-2023-2263

The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.  The new ENIP connections cannot be established if im…

Mitigation only
Fix from $1,950 2023-07-18
1756 En2f Series A Firmware CRITICAL 9.8
CVE-2023-3595

Where this vulnerability exists in the Rockwell Automation 1756 EN2* and 1756 EN3* ControlLogix communication products, it could allow a malicious us…

Mitigation only
Fix from $2,300 2023-07-12
1756 En4tr Firmware HIGH 7.5
CVE-2023-3596

Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a d…

Mitigation only
Fix from $1,950 2023-07-12
Enhanced Him CRITICAL 9.6
CVE-2023-2746

The Rockwell Automation Enhanced HIM software contains an API that the application uses that is not protected sufficiently and uses incorrect Cross…

No fix yet
Fix from $2,300 2023-07-11
Powermonitor 1000 Firmware HIGH 8.8
CVE-2023-2072

The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.  The vulnerable pa…

Mitigation only
Fix from $1,950 2023-07-11