Vulnerabilidades em Rockwell Automation

291 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rockwell Automation soma 274 CVEs catalogadas, das quais nenhuma consta no catálogo CISA KEV de explorações ativas — índice abaixo da média geral do catálogo, o que indica menor pressão de exploração confirmada no momento. Ainda assim, a presença de 41 falhas de severidade crítica e o EPSS de 0,7809 associado a CVE-2023-2915 — o valor mais alto observado no conjunto — sinalizam risco probabilístico elevado para essa vulnerabilidade específica, merecendo atenção prioritária nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que tende a se manifestar de formas variadas em ambientes de tecnologia operacional e requer controles de segmentação e validação em profundidade. Com 7 CVEs surgidas nos últimos 90 dias e ao menos 1 com prova de conceito pública disponível, a superfície de risco permanece ativa e demanda monitoramento contínuo.

CVE-2023-2915HIGHRockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation VulnerabilityEPSS 78.1%CVE-2023-27856HIGHRockwell Automation ThinManager ThinServer Path Traversal DownloadEPSS 77.2%CVE-2023-2917CRITICALRockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation VulnerabilityEPSS 69.4%CVE-2012-6441Rockwell Automation ControlLogix PLC Information ExposureEPSS 54.2%CVE-2020-12028HIGHRockwell Automation FactoryTalk View SEEPSS 53.0%CVE-2020-12027MEDIUMRockwell Automation FactoryTalk View SEEPSS 53.0%CVE-2019-6553A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLiEPSS 50.0%CVE-2020-12029CRITICALRockwell Automation FactoryTalk View SEEPSS 47.0%CVE-2012-6435HIGHRockwell Automation ControlLogix PLC Improper Access ControlEPSS 42.2%CVE-2012-6442HIGHRockwell Automation ControlLogix PLC Improper Access ControlEPSS 33.0%CVE-2012-6438HIGHRockwell Automation ControlLogix PLC Improper Input ValidationEPSS 33.0%CVE-2012-6436HIGHRockwell Automation ControlLogix PLC Improper Input ValidationEPSS 33.0%CVE-2012-6439Rockwell Automation ControlLogix PLC Improper Access ControlEPSS 28.3%CVE-2023-2914HIGHRockwell Automation ThinManager Thinserver Software Vulnerable to Input Validation VulnerabilitiyEPSS 27.0%CVE-2022-38742HIGHRockwell Automation ThinManager Software Vulnerable to Arbitrary Code Execution and Denial-Of-Service AttackEPSS 21.8%CVE-2024-10386CRITICALRockwell Automation FactoryTalk ThinManager Authentication VulnerabilityEPSS 18.9%CVE-2023-27857HIGHRockwell Automation ThinManager ThinServer Heap-Based Buffer OverflowEPSS 18.3%CVE-2018-14829Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a maEPSS 16.1%CVE-2023-27855CRITICALRockwell Automation ThinManager ThinServer Path Traversal UploadEPSS 13.5%CVE-2023-0755CRITICAL The affected products are vulnerable to an improper validation of array index, which could allow an attacker to crash the server and remoteEPSS 11.8%