Vulnerabilities > Rockwellautomation

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2021-27475 Deserialization of Untrusted Data vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized.
local
low complexity
rockwellautomation CWE-502
8.6
2022-03-23 CVE-2021-27476 OS Command Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection.
network
low complexity
rockwellautomation CWE-78
critical
9.8
2022-03-18 CVE-2020-25176 Path Traversal vulnerability in multiple products
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system.
network
low complexity
schneider-electric rockwellautomation xylem CWE-22
critical
9.8
2022-03-18 CVE-2020-25178 Cleartext Transmission of Sensitive Information vulnerability in multiple products
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP.
8.8
2022-03-18 CVE-2020-25180 Use of Hard-coded Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands.
6.5
2022-03-18 CVE-2020-25182 Uncontrolled Search Path Element vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries.
6.7
2022-03-18 CVE-2020-25184 Insufficiently Protected Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x stores the password in plaintext in a file that is in the same directory as the executable file.
5.5
2022-02-24 CVE-2020-14478 XXE vulnerability in Rockwellautomation Factorytalk Services Platform
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content.
local
low complexity
rockwellautomation CWE-611
7.1
2022-02-24 CVE-2020-14480 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation Factorytalk View 10.0
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
local
low complexity
rockwellautomation CWE-312
5.5
2022-02-24 CVE-2020-14481 Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords.
local
low complexity
rockwellautomation CWE-326
7.8