Vulnerabilities > Rockwellautomation > High

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2021-27466 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
7.5
2022-03-23 CVE-2021-27468 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication.
network
low complexity
rockwellautomation CWE-89
7.5
2022-03-23 CVE-2021-27470 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
7.5
2022-03-23 CVE-2021-27472 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
network
low complexity
rockwellautomation CWE-89
7.5
2022-03-23 CVE-2021-27476 OS Command Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection.
network
low complexity
rockwellautomation CWE-78
7.5
2021-06-03 CVE-2021-32926 Unspecified vulnerability in Rockwellautomation Micro800 Firmware and Micrologix 1400 Firmware
When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash.
network
low complexity
rockwellautomation
7.5
2021-03-25 CVE-2021-22659 Classic Buffer Overflow vulnerability in Rockwellautomation Micrologix 1400 Firmware
Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register.
network
low complexity
rockwellautomation CWE-120
7.5
2021-03-18 CVE-2021-22665 Uncontrolled Search Path Element vulnerability in Rockwellautomation Drivetools Add-On Profiles and Drivetools SP
Rockwell Automation DriveTools SP v5.13 and below and Drives AOP v4.12 and below both contain a vulnerability that a local attacker with limited privileges may be able to exploit resulting in privilege escalation and complete control of the system.
local
low complexity
rockwellautomation CWE-427
7.2
2021-03-18 CVE-2020-14516 Use of Password Hash With Insufficient Computational Effort vulnerability in Rockwellautomation Factorytalk Services Platform 6.10.00/6.11.00
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
network
low complexity
rockwellautomation CWE-916
7.5
2021-03-03 CVE-2021-22681 Insufficiently Protected Credentials vulnerability in Rockwellautomation products
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact GuardLogix 5370, 5380; GuardLogix 5570, 5580; SoftLogix 5800.
network
low complexity
rockwellautomation CWE-522
7.5