Записи rockwellautomation
359 опубликованных записей вендора rockwellautomation.
Профиль для исследователя
- Попали в KEV
- 9 · 2,5 %
- С эксплойтом
- 17 · 4,7 %
- Pre-auth RCE
- 39
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- 1436 дн.
Повторяющиеся классы
- CWE-20 Improper Input Validation50
- CWE-400 Uncontrolled Resource Consumption21
- CWE-119 Improper Restriction of Operations within the Bounds of a Memory Buffer18
- CWE-787 Out-of-bounds Write17
- CWE-79 Improper Neutralization of Input During Web Page Generation ('Cross-site Scripting')16
- CWE-287 Improper Authentication15
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
359 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
100Срочно | CVE-2023-20198Готовый эксплойт | Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.cisco · ios xe · CWE-420 | Критическая10,0 | KEV | 99,6 % | 16 окт. 2023 г. |
88Срочно | CVE-2021-22681Готовый эксплойт | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controckwellautomation · factorytalk services platform · CWE-522 | Критическая9,8 | KEV | 63,6 % | 3 мар. 2021 г. |
66На этой неделе | CVE-2018-0172Готовый эксплойт | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticcisco · ios · CWE-20 | Высокая8,6 | KEV | 7,8 % | 28 мар. 2018 г. |
66На этой неделе | CVE-2018-0155Готовый эксплойт | A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Catacisco · ios · CWE-388 | Высокая8,6 | KEV | 7,7 % | 28 мар. 2018 г. |
66На этой неделе | CVE-2018-0173Готовый эксплойт | A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Versiocisco · ios · CWE-20 | Высокая8,6 | KEV | 7,6 % | 28 мар. 2018 г. |
66На этой неделе | CVE-2018-0174Готовый эксплойт | A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthenticcisco · ios · CWE-20 | Высокая8,6 | KEV | 7,6 % | 28 мар. 2018 г. |
66На этой неделе | CVE-2018-0158Готовый эксплойт | A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthecisco · ios · CWE-20 | Высокая8,6 | KEV | 7,2 % | 28 мар. 2018 г. |
66На этой неделе | CVE-2018-0167Готовый эксплойт | Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software,cisco · ios · CWE-119 | Высокая8,8 | KEV | 3,4 % | 28 мар. 2018 г. |
63На этой неделе | CVE-2018-0175Готовый эксплойт | Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IOcisco · ios · CWE-119 | Высокая8,0 | KEV | 3,5 % | 28 мар. 2018 г. |
61На этой неделе | CVE-2023-2915Готовый эксплойт | Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerabilityrockwellautomation · thinmanager thinserver · CWE-20 | Критическая9,1 | — | 81,8 % | 17 авг. 2023 г. |
61На этой неделе | CVE-2023-2917Готовый эксплойт | Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerabilityrockwellautomation · thinmanager thinserver · CWE-20 | Критическая9,8 | — | 72,2 % | 17 авг. 2023 г. |
59В плане | CVE-2019-6553Эксплойта нет | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior.rockwellautomation · rslinx · CWE-121 | Критическая9,8 | — | 66,1 % | 4 апр. 2019 г. |
53В плане | CVE-2023-27856Готовый эксплойт | Rockwell Automation ThinManager ThinServer Path Traversal Downloadrockwellautomation · thinmanager · CWE-22 | Высокая7,5 | — | 77,2 % | 21 мар. 2023 г. |
53В плане | CVE-2010-2965Эксплойта нет | The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with frockwellautomation · 1756-enbt\/a firmware · CWE-863 | Критическая9,8 | — | 47,4 % | 5 авг. 2010 г. |
51В плане | CVE-2017-14463Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,9 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14468Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14473Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14466Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14464Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14471Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14472Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14470Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14469Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 38,0 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14467Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 37,3 % | 5 апр. 2018 г. |
50В плане | CVE-2017-14465Эксплойта нет | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microlrockwellautomation · micrologix 1400 b firmware | Критическая9,8 | — | 35,2 % | 5 апр. 2018 г. |
- CVE-2023-20198100Срочно
Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software.
КритическаяCVSS 10,0KEVГотовый эксплойтEPSS 100 %cisco · ios xe16 окт. 2023 г.
- CVE-2021-2268188Срочно
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix cont
КритическаяCVSS 9,8KEVГотовый эксплойтEPSS 64 %rockwellautomation · factorytalk services platform3 мар. 2021 г.
- CVE-2018-017266На этой неделе
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 8 %cisco · ios28 мар. 2018 г.
- CVE-2018-015566На этой неделе
A vulnerability in the Bidirectional Forwarding Detection (BFD) offload implementation of Cisco Catalyst 4500 Series Switches and Cisco Cata
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 8 %cisco · ios28 мар. 2018 г.
- CVE-2018-017366На этой неделе
A vulnerability in the Cisco IOS Software and Cisco IOS XE Software function that restores encapsulated option 82 information in DHCP Versio
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 8 %cisco · ios28 мар. 2018 г.
- CVE-2018-017466На этой неделе
A vulnerability in the DHCP option 82 encapsulation functionality of Cisco IOS Software and Cisco IOS XE Software could allow an unauthentic
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 8 %cisco · ios28 мар. 2018 г.
- CVE-2018-015866На этой неделе
A vulnerability in the Internet Key Exchange Version 2 (IKEv2) module of Cisco IOS Software and Cisco IOS XE Software could allow an unauthe
ВысокаяCVSS 8,6KEVГотовый эксплойтEPSS 7 %cisco · ios28 мар. 2018 г.
- CVE-2018-016766На этой неделе
Multiple Buffer Overflow vulnerabilities in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software,
ВысокаяCVSS 8,8KEVГотовый эксплойтEPSS 3 %cisco · ios28 мар. 2018 г.
- CVE-2018-017563На этой неделе
Format String vulnerability in the Link Layer Discovery Protocol (LLDP) subsystem of Cisco IOS Software, Cisco IOS XE Software, and Cisco IO
ВысокаяCVSS 8,0KEVГотовый эксплойтEPSS 3 %cisco · ios28 мар. 2018 г.
- CVE-2023-291561На этой неделе
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
КритическаяCVSS 9,1Готовый эксплойтEPSS 82 %rockwellautomation · thinmanager thinserver17 авг. 2023 г.
- CVE-2023-291761На этой неделе
Rockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation Vulnerability
КритическаяCVSS 9,8Готовый эксплойтEPSS 72 %rockwellautomation · thinmanager thinserver17 авг. 2023 г.
- CVE-2019-655359В плане
A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 66 %rockwellautomation · rslinx4 апр. 2019 г.
- CVE-2023-2785653В плане
Rockwell Automation ThinManager ThinServer Path Traversal Download
ВысокаяCVSS 7,5Готовый эксплойтEPSS 77 %rockwellautomation · thinmanager21 мар. 2023 г.
- CVE-2010-296553В плане
The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with f
КритическаяCVSS 9,8Эксплойта нетEPSS 47 %rockwellautomation · 1756-enbt\/a firmware5 авг. 2010 г.
- CVE-2017-1446351В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 39 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446850В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1447350В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446650В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446450В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1447150В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1447250В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1447050В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446950В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 38 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446750В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 37 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.
- CVE-2017-1446550В плане
An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Microl
КритическаяCVSS 9,8Эксплойта нетEPSS 35 %rockwellautomation · micrologix 1400 b firmware5 апр. 2018 г.