Vulnerabilities > Rockwellautomation > Critical

DATE CVE VULNERABILITY TITLE RISK
2020-06-15 CVE-2020-12001 Improper Input Validation vulnerability in Rockwellautomation Factorytalk Linx and Rslinx Classic
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000 Launcher: Version 31 and later Stud, 5000 Logix Designer software: Version 32 and prior is vulnerable.
network
low complexity
rockwellautomation CWE-20
critical
9.8
2020-03-23 CVE-2020-6967 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Services Platform
In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at TCPtcp/8082, which can insecurely deserialize untrusted data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2020-03-16 CVE-2020-6990 Use of Hard-coded Credentials vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file.
network
low complexity
rockwellautomation CWE-798
critical
9.8
2019-07-11 CVE-2019-10970 Unspecified vulnerability in Rockwellautomation Panelview 5510 Firmware
In Rockwell Automation PanelView 5510 (all versions manufactured before March 13, 2019 that have never been updated to v4.003, v5.002, or later), a remote, unauthenticated threat actor with access to an affected PanelView 5510 Graphic Display, upon successful exploit, may boot-up the terminal and gain root-level access to the device’s file system.
network
low complexity
rockwellautomation
critical
9.8
2019-05-01 CVE-2019-10952 Unspecified vulnerability in Rockwellautomation products
An attacker could send a crafted HTTP/HTTPS request to render the web server unavailable and/or lead to remote code execution caused by a stack-based buffer overflow vulnerability.
network
low complexity
rockwellautomation
critical
9.8
2019-04-04 CVE-2018-19282 Resource Exhaustion vulnerability in Rockwellautomation Powerflex 525 AC Drives Firmware 5.001
Rockwell Automation PowerFlex 525 AC Drives 5.001 and earlier allow remote attackers to cause a denial of service by crashing the Common Industrial Protocol (CIP) network stack.
network
low complexity
rockwellautomation CWE-400
critical
9.8
2019-04-04 CVE-2019-6553 Out-of-bounds Write vulnerability in Rockwellautomation Rslinx
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior.
network
low complexity
rockwellautomation CWE-787
critical
9.8
2019-03-26 CVE-2010-5305 Improper Access Control vulnerability in Rockwellautomation products
The potential exists for exposure of the product's password used to restrict unauthorized access to Rockwell PLC5/SLC5/0x/RSLogix 1785-Lx and 1747-L5x controllers.
network
low complexity
rockwellautomation CWE-284
critical
9.8
2018-09-20 CVE-2018-14829 Improper Restriction of Operations within the Bounds of a Memory Buffer vulnerability in Rockwellautomation Rslinx
Rockwell Automation RSLinx Classic Versions 4.00.01 and prior.
network
low complexity
rockwellautomation CWE-119
critical
9.8
2018-04-05 CVE-2017-14473 Unspecified vulnerability in Rockwellautomation Micrologix 1400 B Firmware
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before.
network
low complexity
rockwellautomation
critical
9.8