Vulnerabilities > Rockwellautomation > Medium

DATE CVE VULNERABILITY TITLE RISK
2020-05-19 CVE-2020-12038 Out-of-bounds Write vulnerability in Rockwellautomation products
Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is vulnerable.
4.3
2020-03-16 CVE-2020-6988 Improper Authentication vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller.
network
low complexity
rockwellautomation CWE-287
5.0
2020-03-16 CVE-2020-6984 Use of a Broken or Risky Cryptographic Algorithm vulnerability in Rockwellautomation products
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable.
network
low complexity
rockwellautomation CWE-327
5.0
2020-01-27 CVE-2019-13521 Unspecified vulnerability in Rockwellautomation Arena Simulation 16.00.00
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation.
6.8
2020-01-27 CVE-2019-13519 Type Confusion vulnerability in Rockwellautomation Arena Simulation 16.00.00
A maliciously crafted program file opened by an unsuspecting user of Rockwell Automation Arena Simulation Software version 16.00.00 and earlier may result in the limited exposure of information related to the targeted workstation.
6.8
2019-09-24 CVE-2019-13527 Access of Uninitialized Pointer vulnerability in Rockwellautomation Arena Simulation Software
In Rockwell Automation Arena Simulation Software Cat.
6.8
2019-08-15 CVE-2019-13511 Use After Free vulnerability in Rockwellautomation Arena Simulation Software 16.00.00
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain an INFORMATION EXPOSURE CWE-200.
4.3
2019-08-15 CVE-2019-13510 Use After Free vulnerability in Rockwellautomation Arena Simulation Software
Rockwell Automation Arena Simulation Software versions 16.00.00 and earlier contain a USE AFTER FREE CWE-416.
6.8
2019-04-25 CVE-2019-10955 Open Redirect vulnerability in Rockwellautomation products
In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix GuardLogix controllers) v30.014 and earlier, an open redirect vulnerability could allow a remote unauthenticated attacker to input a malicious link to redirect users to a malicious site that could run or download arbitrary malware on the user’s machine.
5.8
2018-12-26 CVE-2018-19616 Improper Authentication vulnerability in Rockwellautomation Powermonitor 1000 Firmware 1408Em3Aentb
An issue was discovered in Rockwell Automation Allen-Bradley PowerMonitor 1000.
6.8