Vulnerabilities > Rockwellautomation > High

DATE CVE VULNERABILITY TITLE RISK
2023-10-27 CVE-2023-46289 Improper Input Validation vulnerability in Rockwellautomation Factorytalk View
Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline.
network
low complexity
rockwellautomation CWE-20
7.5
2023-10-27 CVE-2023-46290 Improper Authentication vulnerability in Rockwellautomation Factorytalk Services Platform
Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform .
network
high complexity
rockwellautomation CWE-287
8.1
2023-08-17 CVE-2023-2914 Integer Overflow or Wraparound vulnerability in Rockwellautomation Thinmanager Thinserver 13.1.0
The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, an integer overflow condition exists in the affected products.
network
low complexity
rockwellautomation CWE-190
7.5
2023-08-08 CVE-2023-2423 Incorrect Calculation vulnerability in Rockwellautomation Armor Powerflex Firmware 1.003
A vulnerability was discovered in the Rockwell Automation Armor PowerFlex device when the product sends communications to the local event log.
network
low complexity
rockwellautomation CWE-682
7.5
2023-07-18 CVE-2023-2263 Resource Exhaustion vulnerability in Rockwellautomation Kinetix 5700 Firmware 13.001
The Rockwell Automation Kinetix 5700 DC Bus Power Supply Series A is vulnerable to CIP fuzzing.
network
low complexity
rockwellautomation CWE-400
7.5
2023-07-12 CVE-2023-3596 Out-of-bounds Write vulnerability in Rockwellautomation products
Where this vulnerability exists in the Rockwell Automation 1756-EN4* Ethernet/IP communication products, it could allow a malicious user to cause a denial of service by asserting the target system through maliciously crafted CIP messages.
network
low complexity
rockwellautomation CWE-787
7.5
2023-07-11 CVE-2023-2072 Cross-site Scripting vulnerability in Rockwellautomation Powermonitor 1000 Firmware
The Rockwell Automation PowerMonitor 1000 contains stored cross-site scripting vulnerabilities within the web page of the product.
network
low complexity
rockwellautomation CWE-79
8.8
2023-06-13 CVE-2023-2637 Use of Hard-coded Credentials vulnerability in Rockwellautomation products
Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies.  Hard-coded cryptographic key may lead to privilege escalation.  This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them administrative privileges to the FactoryTalk Policy Manger database.
local
low complexity
rockwellautomation CWE-798
8.2
2023-06-13 CVE-2023-2778 Resource Exhaustion vulnerability in Rockwellautomation Factorytalk Transaction Manager 13.00/13.10
A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager.
network
low complexity
rockwellautomation CWE-400
7.5
2023-05-11 CVE-2023-2443 Inadequate Encryption Strength vulnerability in Rockwellautomation Thinmanager
Rockwell Automation ThinManager product allows the use of medium strength ciphers.
network
low complexity
rockwellautomation CWE-326
7.5