Vulnerabilities > Rockwellautomation

DATE CVE VULNERABILITY TITLE RISK
2022-03-18 CVE-2020-25180 Use of Hard-coded Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands.
6.5
2022-03-18 CVE-2020-25182 Uncontrolled Search Path Element vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries.
6.7
2022-03-18 CVE-2020-25184 Insufficiently Protected Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file.
5.5
2022-02-24 CVE-2020-14478 XXE vulnerability in Rockwellautomation Factorytalk Services Platform
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content.
local
low complexity
rockwellautomation CWE-611
7.1
2022-02-24 CVE-2020-14480 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation Factorytalk View 10.0
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
local
low complexity
rockwellautomation CWE-312
5.5
2022-02-24 CVE-2020-14481 Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords.
local
low complexity
rockwellautomation CWE-326
7.8
2022-02-24 CVE-2020-14502 Cross-site Scripting vulnerability in Rockwellautomation products
The web interface of the 1734-AENTR communication module is vulnerable to stored XSS.
network
low complexity
rockwellautomation CWE-79
6.1
2022-02-24 CVE-2020-14504 Improper Authentication vulnerability in Rockwellautomation products
The web interface of the 1734-AENTR communication module mishandles authentication for HTTP POST requests.
network
low complexity
rockwellautomation CWE-287
5.3
2021-07-09 CVE-2021-33012 Unspecified vulnerability in Rockwellautomation Micrologix 1100 Firmware
Rockwell Automation MicroLogix 1100, all versions, allows a remote, unauthenticated attacker sending specially crafted commands to cause the PLC to fault when the controller is switched to RUN mode, which results in a denial-of-service condition.
network
low complexity
rockwellautomation
8.6
2021-06-03 CVE-2021-32926 Unspecified vulnerability in Rockwellautomation Micro800 Firmware and Micrologix 1400 Firmware
When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash.
network
low complexity
rockwellautomation
7.5