Vulnerabilities > Rockwellautomation > High

DATE CVE VULNERABILITY TITLE RISK
2020-11-26 CVE-2020-27255 Unspecified vulnerability in Rockwellautomation Factorytalk Linx 6.00/6.10/6.11
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior.
network
low complexity
rockwellautomation
7.5
2020-11-26 CVE-2020-27253 Unspecified vulnerability in Rockwellautomation Factorytalk Linx 6.00/6.10/6.11
A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior.
network
low complexity
rockwellautomation
7.5
2020-10-19 CVE-2020-6085 Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent 4.003
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003.
network
low complexity
rockwellautomation CWE-120
7.5
2020-10-19 CVE-2020-6084 Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent 4.003
An exploitable denial of service vulnerability exists in the ENIP Request Path Logical Segment functionality of Allen-Bradley Flex IO 1794-AENT/B 4.003.
network
low complexity
rockwellautomation CWE-120
7.5
2020-10-14 CVE-2020-6083 Classic Buffer Overflow vulnerability in Rockwellautomation Allen-Bradley Flex IO 1794-Aent/B Firmware 4.003
An exploitable denial of service vulnerability exists in the ENIP Request Path Port Segment functionality of Allen-Bradley Flex IO 1794-AENT/B.
network
low complexity
rockwellautomation CWE-120
7.5
2020-10-14 CVE-2020-6087 Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent/B Firmware 4.003
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B.
network
low complexity
rockwellautomation CWE-120
7.5
2020-10-14 CVE-2020-6086 Classic Buffer Overflow vulnerability in Rockwellautomation Flex I/O 1794-Aent/B Firmware 4.003
An exploitable denial of service vulnerability exists in the ENIP Request Path Data Segment functionality of Allen-Bradley Flex IO 1794-AENT/B.
network
low complexity
rockwellautomation CWE-120
7.5
2020-07-20 CVE-2020-12031 Out-of-bounds Write vulnerability in Rockwellautomation Factorytalk View
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution.
local
low complexity
rockwellautomation CWE-787
7.8
2020-07-20 CVE-2020-12028 Missing Authentication for Critical Function vulnerability in Rockwellautomation Factorytalk View
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions.
network
low complexity
rockwellautomation CWE-306
8.1
2020-07-20 CVE-2020-12029 Unspecified vulnerability in Rockwellautomation Factorytalk View
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory.
local
low complexity
rockwellautomation
7.8