Vulnerabilities > Rockwellautomation > High

DATE CVE VULNERABILITY TITLE RISK
2022-07-27 CVE-2020-6998 Improper Input Validation vulnerability in Rockwellautomation products
The connection establishment algorithm found in Rockwell Automation CompactLogix 5370 and ControlLogix 5570 versions 33 and prior does not sufficiently manage its control flow during execution, creating an infinite loop.
network
low complexity
rockwellautomation CWE-20
8.6
2022-06-02 CVE-2022-1797 Unspecified vulnerability in Rockwellautomation products
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault.
network
low complexity
rockwellautomation
8.6
2022-05-17 CVE-2022-1118 Unspecified vulnerability in Rockwellautomation products
Connected Components Workbench (v13.00.00 and prior), ISaGRAF Workbench (v6.0 though v6.6.9), and Safety Instrumented System Workstation (v1.2 and prior (for Trusted Controllers)) do not limit the objects that can be deserialized.
local
low complexity
rockwellautomation
7.8
2022-04-01 CVE-2021-32960 Incorrect Authorization vulnerability in Rockwellautomation Factorytalk Services Platform
Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name.
network
low complexity
rockwellautomation CWE-863
8.8
2022-04-01 CVE-2022-1159 Code Injection vulnerability in Rockwellautomation products
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.
network
low complexity
rockwellautomation CWE-94
7.2
2022-03-23 CVE-2021-27471 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
The parsing mechanism that processes certain file types does not provide input sanitization for file paths.
local
low complexity
rockwellautomation CWE-22
8.6
2022-03-23 CVE-2021-27473 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction.
local
low complexity
rockwellautomation CWE-22
8.2
2022-03-23 CVE-2021-27474 Unspecified vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services.
network
low complexity
rockwellautomation
7.5
2022-03-23 CVE-2021-27475 Deserialization of Untrusted Data vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized.
local
low complexity
rockwellautomation CWE-502
8.6
2022-03-18 CVE-2020-25178 Cleartext Transmission of Sensitive Information vulnerability in multiple products
ISaGRAF Workbench communicates with Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x using TCP/IP.
8.8