Vulnerabilidades em Rockwell Automation

310 resultados
Análise Vexday

O portfólio de vulnerabilidades da Rockwell Automation soma 274 CVEs catalogadas, das quais nenhuma consta no catálogo CISA KEV de explorações ativas — índice abaixo da média geral do catálogo, o que indica menor pressão de exploração confirmada no momento. Ainda assim, a presença de 41 falhas de severidade crítica e o EPSS de 0,7809 associado a CVE-2023-2915 — o valor mais alto observado no conjunto — sinalizam risco probabilístico elevado para essa vulnerabilidade específica, merecendo atenção prioritária nas rotinas de patch. O tipo de falha mais recorrente é CWE-20 (validação imprópria de entrada), padrão que tende a se manifestar de formas variadas em ambientes de tecnologia operacional e requer controles de segmentação e validação em profundidade. Com 7 CVEs surgidas nos últimos 90 dias e ao menos 1 com prova de conceito pública disponível, a superfície de risco permanece ativa e demanda monitoramento contínuo.

CVE-2023-1834CRITICALRockwell Automation Kinetix 5500 Vulnerable to Open Port ExploitationEPSS 1.3%CVE-2023-2263HIGHRockwell Automation Kinetix 5700 DC Bus Power Supply Series A – CIP Message Attack Could Cause Denial-Of-ServiceEPSS 1.2%CVE-2023-2778HIGHRockwell Automation FactoryTalk Transaction Manager Vulnerable to Denial-Of-ServiceEPSS 1.2%CVE-2022-3752HIGHRockwell Automation GuardLogix and ControlLogix controllers Vulnerable to Denial-Of-Service AttackEPSS 1.2%CVE-2023-2423HIGHRockwell Automation Armor PowerFlex Vulnerable to Denial-Of-ServiceEPSS 1.2%CVE-2022-2179MEDIUMICSA-22-188-01 Rockwell Automation MicroLogix Improper Restriction of Rendered UI Layers or FramesEPSS 1.2%CVE-2022-38744HIGHFactoryTalk Alarm and Events Server Vulnerable to Denial-Of-Service AttackEPSS 1.2%CVE-2020-25180MEDIUMRockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic KeyEPSS 1.2%CVE-2020-14502MEDIUMThe web interface of the 1734-AENTR communication module is vulnerable to stored XSS. A remote, unauthenticated attacker could store a malicEPSS 1.0%CVE-2024-21915CRITICALRockwell Automation FactoryTalk® Service Platform Elevated Privileges Vulnerability Through Web Service FunctionalityEPSS 1.0%CVE-2023-5908CRITICALHeap Based Buffer Overflow in PTC KEPServerExEPSS 1.0%CVE-2024-7961HIGHRockwell Automation Path Traversal Vulnerability in Pavilion8®EPSS 1.0%CVE-2023-2072HIGHRockwell Automation PowerMonitor 1000 Cross-Site Scripting VulnerabilityEPSS 0.9%CVE-2023-29462HIGHRockwell Automation Arena Simulation Software Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-46289HIGHRockwell Automation FactoryTalk® View Site Edition Vulnerable to Improper Input ValidationEPSS 0.9%CVE-2024-12372CRITICALRockwell Automation PowerMonitor™ 1000 Denial of ServiceEPSS 0.9%CVE-2024-21917CRITICALRockwell Automation FactoryTalk® Service Platform Service Token VulnerabilityEPSS 0.9%CVE-2023-29460HIGHRockwell Automation Arena Simulation Software Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-29461HIGHRockwell Automation Arena Simulation Software Remote Code Execution VulnerabilityEPSS 0.9%CVE-2023-0027MEDIUMRockwell Automation Modbus TCP AOI Server Could Leak Sensitive InformationEPSS 0.8%