Vulnerabilities > Rockwellautomation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2020-10-19 | CVE-2020-6085 | Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent 4.003 An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. | 7.5 |
2020-10-19 | CVE-2020-6084 | Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent 4.003 An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003. | 7.5 |
2020-10-14 | CVE-2020-6083 | Classic Buffer Overflow vulnerability in Rockwellautomation Allen-Bradley Flex IO 1794-Aent/B Firmware 4.003 An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. | 7.5 |
2020-10-14 | CVE-2020-6087 | Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent/B Firmware 4.003 An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. | 7.5 |
2020-10-14 | CVE-2020-6086 | Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent/B Firmware 4.003 An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B. | 7.5 |
2020-07-20 | CVE-2020-12031 | Out-of-bounds Write vulnerability in Rockwellautomation Factorytalk View In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. | 7.8 |
2020-07-20 | CVE-2020-12028 | Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. | 8.1 |
2020-07-20 | CVE-2020-12027 | Unspecified vulnerability in Rockwellautomation Factorytalk View All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. | 4.3 |
2020-07-20 | CVE-2020-12029 | Unspecified vulnerability in Rockwellautomation Factorytalk View All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. | 7.8 |
2020-07-14 | CVE-2020-12025 | XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02 Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program. | 3.3 |