Vulnerabilities > Rockwellautomation > Critical

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2021-27470 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2022-03-23 CVE-2021-27472 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
network
low complexity
rockwellautomation CWE-89
critical
9.8
2022-03-23 CVE-2021-27476 OS Command Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection.
network
low complexity
rockwellautomation CWE-78
critical
9.8
2022-03-18 CVE-2020-25176 Path Traversal vulnerability in multiple products
Some commands used by the Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x eXchange Layer (IXL) protocol perform various file operations in the file system.
network
low complexity
schneider-electric rockwellautomation xylem CWE-22
critical
9.8
2021-03-18 CVE-2020-14516 Unspecified vulnerability in Rockwellautomation Factorytalk Services Platform 6.10.00/6.11.00
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
network
low complexity
rockwellautomation
critical
10.0
2021-03-03 CVE-2021-22681 Insufficiently Protected Credentials vulnerability in Rockwellautomation products
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
network
low complexity
rockwellautomation CWE-522
critical
9.8
2021-01-14 CVE-2020-27267 Out-of-bounds Write vulnerability in multiple products
KEPServerEX v6.0 to v6.9, ThingWorx Kepware Server v6.8 and v6.9, ThingWorx Industrial Connectivity (all versions), OPC-Aggregator (all versions), Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server v7.68.804 and v7.66, and Software Toolbox TOP Server all 6.x versions, are vulnerable to a heap-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.1
2021-01-14 CVE-2020-27265 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions are vulnerable to a stack-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.8
2021-01-14 CVE-2020-27263 Out-of-bounds Write vulnerability in multiple products
KEPServerEX: v6.0 to v6.9, ThingWorx Kepware Server: v6.8 and v6.9, ThingWorx Industrial Connectivity: All versions, OPC-Aggregator: All versions, Rockwell Automation KEPServer Enterprise, GE Digital Industrial Gateway Server: v7.68.804 and v7.66, Software Toolbox TOP Server: All 6.x versions, are vulnerable to a heap-based buffer overflow.
network
low complexity
ptc ge rockwellautomation softwaretoolbox CWE-787
critical
9.1
2020-11-26 CVE-2020-27251 Unspecified vulnerability in Rockwellautomation Factorytalk Linx 6.00/6.10/6.11
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior.
network
low complexity
rockwellautomation
critical
9.8