Skip to main content

Vendor archive

rockwellautomation CVEs

Beta · best-effort

348 CVEs tagged to vendor rockwellautomation76 Critical, 214 High, 52 Medium, 6 Low, 0 Unrated.

CVE-2022-2848

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.1 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-2825

Published Mar 29, 2023

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Kepware KEPServerEX 6.11.718.0. Authentication is not required to exploit this vu…

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-27857

Published Mar 22, 2023

In affected versions, a heap-based buffer over-read condition occurs when the message field indicates more data than is present in the message field in Rockwell Automation's T…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27856

Published Mar 22, 2023

In affected versions, path traversal exists when processing a message of type 8 in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker can exploit…

CVSS 7.5 · High
Vendor/product tagsBeta · best-effort

CVE-2023-27855

Published Mar 22, 2023

In affected versions, a path traversal exists when processing a message in Rockwell Automation's ThinManager ThinServer. An unauthenticated remote attacker could potentially explo…

CVSS 9.8 · Critical
Vendor/product tagsBeta · best-effort

CVE-2023-0755

Published Feb 23, 2023

The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2023-0754

Published Feb 23, 2023

The affected products are vulnerable to an integer overflow or wraparound, which could  allow an attacker to crash the server and remotely execute arbitrary code.

CVSS 9.8 · Critical
evidence mentions
1
Buzz score
11.9

CVE-2022-3156

Published Dec 27, 2022

A remote code execution vulnerability exists in Rockwell Automation Studio 5000 Logix Emulate software.  Users are granted elevated permissions on certain product services when th…

CVSS 7.8 · High
evidence mentions
1
Buzz score
11.9
Vendor/product tagsBeta · best-effort

CVE-2022-3158

Published Oct 17, 2022

Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lack…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2022-38742

Published Sep 23, 2022

Rockwell Automation ThinManager ThinServer versions 11.0.0 - 13.0.0 is vulnerable to a heap-based buffer overflow. An attacker could send a specifically crafted TFTP or HTTPS requ…

CVSS 8.1 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2465

Published Aug 25, 2022

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Deserialization of Untrusted Data vulnerability. ISaGRAF Workbench does not limit the o…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2464

Published Aug 25, 2022

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. Crafted malicious files can allow an attacker to traverse…

CVSS 7.7 · High
Vendor/product tagsBeta · best-effort

CVE-2022-2463

Published Aug 25, 2022

Rockwell Automation ISaGRAF Workbench software versions 6.0 through 6.6.9 are affected by a Path Traversal vulnerability. A crafted malicious .7z exchange file may allow an attack…

CVSS 6.1 · Medium
Vendor/product tagsBeta · best-effort
Showing 151-175 of 348 CVEsPage 7 of 14