Skip to main content

Vendor archive

rockwellautomation CVEs

Beta · best-effort

348 CVEs tagged to vendor rockwellautomation76 Critical, 214 High, 52 Medium, 6 Low, 0 Unrated.

CVE-2024-12175

Published Dec 19, 2024

Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11364

Published Dec 19, 2024

Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software t…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11157

Published Dec 19, 2024

A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-12130

Published Dec 5, 2024

An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11158

Published Dec 5, 2024

An “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11156

Published Dec 5, 2024

An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memo…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-11155

Published Dec 5, 2024

A “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resou…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-37365

Published Nov 12, 2024

A remote code execution vulnerability exists in the affected product. The vulnerability allows users to save projects within the public directory allowing anyone with local access…

CVSS 7.0 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10387

Published Oct 25, 2024

CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted message…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-10386

Published Oct 25, 2024

CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-6436

Published Sep 27, 2024

An input validation vulnerability exists in the Rockwell Automation Sequence Manager™ which could allow a malicious user to send malformed packets to the server and cause a denial…

CVSS 8.7 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7961

Published Sep 12, 2024

A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in…

CVSS 8.6 · High
Vendor/product tagsBeta · best-effort

CVE-2024-7960

Published Sep 12, 2024

The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to hav…

CVSS 8.8 · High
Vendor/product tagsBeta · best-effort

CVE-2024-8533

Published Sep 12, 2024

A privilege escalation vulnerability exists in the Rockwell Automation affected products. The vulnerability occurs due to improper default file permissions allowing users to exfil…

CVSS 7.7 · High

CVE-2024-45826

Published Sep 12, 2024

CVE-2024-45826 IMPACT Due to improper input validation, a path traversal and remote code execution vulnerability exists when the ThinManager® processes a crafted POST request. If…

CVSS 8.5 · High
Vendor/product tagsBeta · best-effort

CVE-2024-45823

Published Sep 12, 2024

CVE-2024-45823 IMPACT An authentication bypass vulnerability exists in the affected product. The vulnerability exists due to shared secrets across accounts and could allow a th…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-45824

Published Sep 12, 2024

CVE-2024-45824 IMPACT A remote code vulnerability exists in the affected products. The vulnerability occurs when chained with Path Traversal, Command Injection, and XSS Vulnera…

CVSS 9.2 · Critical
Vendor/product tagsBeta · best-effort

CVE-2024-7988

Published Aug 26, 2024

A remote code execution vulnerability exists in the Rockwell Automation ThinManager® ThinServer™ that allows a threat actor to execute arbitrary code with System privileges. This…

CVSS 9.3 · Critical
Vendor/product tagsBeta · best-effort
Showing 51-75 of 348 CVEsPage 3 of 14