Vulnerabilities > Rockwellautomation > Low

DATE CVE VULNERABILITY TITLE RISK
2022-02-24 CVE-2020-14481 Inadequate Encryption Strength vulnerability in Rockwellautomation Factorytalk View 10.0
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords.
local
low complexity
rockwellautomation CWE-326
2.1
2022-02-24 CVE-2020-14480 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation Factorytalk View 10.0
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
local
low complexity
rockwellautomation CWE-312
2.1
2020-12-29 CVE-2020-5806 Allocation of Resources Without Limits or Throttling vulnerability in Rockwellautomation Factorytalk Linx 6.00/6.10/6.11
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll.
local
low complexity
rockwellautomation CWE-770
2.1
2020-03-16 CVE-2020-6980 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.
local
low complexity
rockwellautomation CWE-312
2.1