Vulnerabilities > Rockwellautomation > Low

DATE CVE VULNERABILITY TITLE RISK
2020-07-14 CVE-2020-12025 XXE vulnerability in Rockwellautomation Studio 5000 Logix Designer 32.00/32.01/32.02
Rockwell Automation Logix Designer Studio 5000 Versions 32.00, 32.01, and 32.02 vulnerable to an xml external entity (XXE) vulnerability, which may allow an attacker to view hostnames or other resources from the program.
local
low complexity
rockwellautomation CWE-611
3.3
2020-03-16 CVE-2020-6980 Cleartext Storage of Sensitive Information vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be able to gather SMTP server authentication data as it is written to the project file in cleartext.
local
low complexity
rockwellautomation CWE-312
3.3
2019-08-15 CVE-2019-13511 Use After Free vulnerability in Rockwellautomation Arena
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200.
local
low complexity
rockwellautomation CWE-416
3.3
2017-02-13 CVE-2016-9338 Unspecified vulnerability in Rockwellautomation products
An issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 controller 1763-L16AWA, Series A and B, Version 14.000 and prior versions; 1763-L16BBB, Series A and B, Version 14.000 and prior versions; 1763-L16BWA, Series A and B, Version 14.000 and prior versions; and 1763-L16DWD, Series A and B, Version 14.000 and prior versions.
network
low complexity
rockwellautomation
2.7