Vulnerabilities > Rockwellautomation
DATE | CVE | VULNERABILITY TITLE | RISK |
---|---|---|---|
2019-05-01 | CVE-2019-10952 | Unspecified vulnerability in Rockwellautomation products An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability. | 9.8 |
2019-05-01 | CVE-2019-10954 | Unspecified vulnerability in Rockwellautomation products An attacker could send crafted SMTP packets to cause a denial-of-service condition where the controller enters a major non-recoverable faulted state (MNRF) in CompactLogix 5370 L1, L2, and L3 Controllers, Compact GuardLogix 5370 controllers, and Armor Compact GuardLogix 5370 Controllers Versions 20 - 30 and earlier. | 7.5 |
2019-04-25 | CVE-2019-10955 | Open Redirect vulnerability in Rockwellautomation products In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine. | 6.1 |
2019-04-04 | CVE-2018-19282 | Resource Exhaustion vulnerability in Rockwellautomation Powerflex 525 AC Drives Firmware 5.001 Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack. | 9.8 |
2019-04-04 | CVE-2019-6553 | Out-of-bounds Write vulnerability in Rockwellautomation Rslinx A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. | 9.8 |
2019-03-27 | CVE-2018-19016 | Improper Input Validation vulnerability in Rockwellautomation products Rockwell Automation EtherNet/IP Web Server Modules 1756-EWEB (includes 1756-EWEBK) Version 5.001 and earlier, and CompactLogix 1768-EWEB Version 2.005 and earlier. | 7.5 |
2019-03-26 | CVE-2013-2805 | Out-of-bounds Read vulnerability in Rockwellautomation Rslinx Enterprise Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receives a datagram with an incorrect value in the “Record Data Size” field. | 7.5 |
2019-03-26 | CVE-2010-5305 | Improper Access Control vulnerability in Rockwellautomation products The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers. | 9.8 |
2019-03-26 | CVE-2013-2807 | Out-of-bounds Read vulnerability in Rockwellautomation Rslinx Enterprise Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. | 7.5 |
2019-03-26 | CVE-2013-2806 | Integer Overflow or Wraparound vulnerability in Rockwellautomation Rslinx Enterprise Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “End of Current Record” field. | 7.5 |