rockwellautomation records
359 published records for vendor rockwellautomation.
Researcher profile
- Entered KEV
- 9 · 2.5%
- Weaponized
- 17 · 4.7%
- Pre-auth RCE
- 39
- With a fix record
- 0%
- Median publish → KEV
- 1436 days
Recurring classes
- CWE-20 Improper Input Validation50
- CWE-400 Uncontrolled Resource Consumption21
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-787 Out-of-bounds Write17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-287 Improper Authentication15
The weakness classes this vendor ships most often: where to look.
CWEAll records
359 records| Action | CVE | Vulnerability | Severity | KEV | EPSS | Published |
|---|---|---|---|---|---|---|
100Now | CVE-2023-20198Weaponized | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Critical10.0 | KEV | 99.6% | Oct 16, 2023 |
88Now | CVE-2021-22681Weaponized | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controckwellautomation · factorytalk services platform · CWE-522 | Critical9.8 | KEV | 63.6% | Mar 3, 2021 |
66This week | CVE-2018-0172Weaponized | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticcisco · ios · CWE-20 | High8.6 | KEV | 7.8% | Mar 28, 2018 |
66This week | CVE-2018-0155Weaponized | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catacisco · ios · CWE-388 | High8.6 | KEV | 7.7% | Mar 28, 2018 |
66This week | CVE-2018-0173Weaponized | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Versiocisco · ios · CWE-20 | High8.6 | KEV | 7.6% | Mar 28, 2018 |
66This week | CVE-2018-0174Weaponized | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticcisco · ios · CWE-20 | High8.6 | KEV | 7.6% | Mar 28, 2018 |
66This week | CVE-2018-0158Weaponized | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | High8.6 | KEV | 7.2% | Mar 28, 2018 |
66This week | CVE-2018-0167Weaponized | Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software,cisco · ios · CWE-119 | High8.8 | KEV | 3.4% | Mar 28, 2018 |
63This week | CVE-2018-0175Weaponized | Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOcisco · ios · CWE-119 | High8.0 | KEV | 3.5% | Mar 28, 2018 |
61This week | CVE-2023-2915Weaponized | Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerabilityrockwellautomation · thinmanager thinserver · CWE-20 | Critical9.1 | — | 81.8% | Aug 17, 2023 |
61This week | CVE-2023-2917Weaponized | Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerabilityrockwellautomation · thinmanager thinserver · CWE-20 | Critical9.8 | — | 72.2% | Aug 17, 2023 |
59Plan | CVE-2019-6553No exploit | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior.rockwellautomation · rslinx · CWE-121 | Critical9.8 | — | 66.1% | Apr 4, 2019 |
53Plan | CVE-2023-27856Weaponized | Rockwell Automation ThinManager ThinServer Path Traversal Downloadrockwellautomation · thinmanager · CWE-22 | High7.5 | — | 77.2% | Mar 21, 2023 |
53Plan | CVE-2010-2965No exploit | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Critical9.8 | — | 47.4% | Aug 5, 2010 |
51Plan | CVE-2017-14463No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.9% | Apr 5, 2018 |
50Plan | CVE-2017-14468No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14473No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14466No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14464No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14471No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14472No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14470No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14469No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 38.0% | Apr 5, 2018 |
50Plan | CVE-2017-14467No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 37.3% | Apr 5, 2018 |
50Plan | CVE-2017-14465No exploit | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Critical9.8 | — | 35.2% | Apr 5, 2018 |
- CVE-2023-20198100Now
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
CriticalCVSS 10.0KEVWeaponizedEPSS 100%cisco · ios xeOct 16, 2023
- CVE-2021-2268188Now
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont
CriticalCVSS 9.8KEVWeaponizedEPSS 64%rockwellautomation · factorytalk services platformMar 3, 2021
- CVE-2018-017266This week
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic
HighCVSS 8.6KEVWeaponizedEPSS 8%cisco · iosMar 28, 2018
- CVE-2018-015566This week
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Cata
HighCVSS 8.6KEVWeaponizedEPSS 8%cisco · iosMar 28, 2018
- CVE-2018-017366This week
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Versio
HighCVSS 8.6KEVWeaponizedEPSS 8%cisco · iosMar 28, 2018
- CVE-2018-017466This week
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic
HighCVSS 8.6KEVWeaponizedEPSS 8%cisco · iosMar 28, 2018
- CVE-2018-015866This week
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthe
HighCVSS 8.6KEVWeaponizedEPSS 7%cisco · iosMar 28, 2018
- CVE-2018-016766This week
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software,
HighCVSS 8.8KEVWeaponizedEPSS 3%cisco · iosMar 28, 2018
- CVE-2018-017563This week
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IO
HighCVSS 8.0KEVWeaponizedEPSS 3%cisco · iosMar 28, 2018
- CVE-2023-291561This week
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
CriticalCVSS 9.1WeaponizedEPSS 82%rockwellautomation · thinmanager thinserverAug 17, 2023
- CVE-2023-291761This week
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
CriticalCVSS 9.8WeaponizedEPSS 72%rockwellautomation · thinmanager thinserverAug 17, 2023
- CVE-2019-655359Plan
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior.
CriticalCVSS 9.8No exploitEPSS 66%rockwellautomation · rslinxApr 4, 2019
- CVE-2023-2785653Plan
Rockwell Automation ThinManager ThinServer Path Traversal Download
HighCVSS 7.5WeaponizedEPSS 77%rockwellautomation · thinmanagerMar 21, 2023
- CVE-2010-296553Plan
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
CriticalCVSS 9.8No exploitEPSS 47%rockwellautomation · 1756-enbt\/a firmwareAug 5, 2010
- CVE-2017-1446351Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 39%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446850Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1447350Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446650Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446450Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1447150Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1447250Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1447050Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446950Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 38%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446750Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 37%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018
- CVE-2017-1446550Plan
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
CriticalCVSS 9.8No exploitEPSS 35%rockwellautomation · micrologix 1400 b firmwareApr 5, 2018