Vulnerabilities > Rockwellautomation > Medium

DATE CVE VULNERABILITY TITLE RISK
2023-05-11 CVE-2023-29026 Cross-site Scripting vulnerability in Rockwellautomation products
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface.
network
low complexity
rockwellautomation CWE-79
5.9
2023-05-11 CVE-2023-29027 Cross-site Scripting vulnerability in Rockwellautomation products
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface.
network
low complexity
rockwellautomation CWE-79
5.9
2023-05-11 CVE-2023-29028 Cross-site Scripting vulnerability in Rockwellautomation products
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface.
network
low complexity
rockwellautomation CWE-79
5.9
2023-05-11 CVE-2023-29029 Cross-site Scripting vulnerability in Rockwellautomation products
A cross site scripting vulnerability was discovered in Rockwell Automation's ArmorStart ST product that could potentially allow a malicious user with admin privileges and network access to view user data and modify the web interface.
network
low complexity
rockwellautomation CWE-79
5.9
2023-03-17 CVE-2023-0027 Information Exposure vulnerability in Rockwellautomation Modbus TCP Server ADD on Instructions 2.00.00/2.00.03
Rockwell Automation Modbus TCP Server AOI prior to 2.04.00 is vulnerable to an unauthorized user sending a malformed message that could cause the controller to respond with a copy of the most recent response to the last valid request.
network
low complexity
rockwellautomation CWE-200
4.3
2022-12-16 CVE-2022-46670 Cross-site Scripting vulnerability in Rockwellautomation products
Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution.
network
low complexity
rockwellautomation CWE-79
6.1
2022-07-20 CVE-2022-2179 Improper Restriction of Rendered UI Layers or Frames vulnerability in Rockwellautomation Micrologix 1100 Firmware and Micrologix 1400 Firmware
The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks.
network
low complexity
rockwellautomation CWE-1021
6.5
2022-04-01 CVE-2022-1018 XXE vulnerability in Rockwellautomation products
When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file.
local
low complexity
rockwellautomation CWE-611
5.5
2022-03-18 CVE-2020-25180 Use of Hard-coded Credentials vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x includes the functionality of setting a password that is required to execute privileged commands.
6.5
2022-03-18 CVE-2020-25182 Uncontrolled Search Path Element vulnerability in multiple products
Rockwell Automation ISaGRAF Runtime Versions 4.x and 5.x searches for and loads DLLs as dynamic libraries.
6.7