PatchSiren

Rockwell Automation CVE debriefs · Page 3

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Rockwell Automation CVE published 2025-01-30

CVE-2025-0498

CVE-2025-0498 is a high-severity data exposure issue in Rockwell Automation FactoryTalk AssetCentre. In versions prior to V15.00.001, FactoryTalk Security user tokens were stored insecurely, which could allow a threat actor to steal a token and impersonate another user. CISA published the advisory on 2025-01-30 under ICSA-25-030-05.

HIGH Rockwell Automation CVE published 2025-01-30

CVE-2025-0497

CVE-2025-0497 is a high-severity data exposure issue in Rockwell Automation FactoryTalk AssetCentre. According to CISA’s advisory, versions prior to V15.00.001 can store credentials in the configuration files used by EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages. The issue was publicly disclosed on 2025-01-30.

CRITICAL Rockwell Automation CVE published 2025-01-30

CVE-2025-0477

CVE-2025-0477 affects Rockwell Automation FactoryTalk AssetCentre versions prior to V15.00.001. CISA’s advisory says the issue is a weak encryption methodology that could allow a threat actor to extract passwords belonging to other users of the application. The published CVSS 3.1 score is 9.8 (Critical), so this should be treated as a high-priority remediation item for any environment running affected releases.

HIGH Rockwell Automation CVE published 2025-01-28

CVE-2025-24482

CVE-2025-24482 is a high-severity local code injection issue in Rockwell Automation FactoryTalk View Site Edition affecting all versions prior to 15.0. CISA says incorrect default permissions can allow DLLs to be executed with higher-level permissions. Rockwell’s guidance is to upgrade to V15.0 or apply the patch and use compensating controls such as restricting physical access and limiting access to Port 8091.

HIGH Rockwell Automation CVE published 2025-01-28

CVE-2025-24481

CVE-2025-24481 affects Rockwell Automation FactoryTalk View Site Edition versions prior to 15.0. According to the CISA CSAF advisory, the issue stems from incorrect permissions assigned to the remote debugger port, which can allow unauthenticated access to system configuration. Rockwell’s published mitigations center on upgrading to V15.0 or applying the vendor patch, and restricting access to Port 8091.

CRITICAL Rockwell Automation CVE published 2025-01-28

CVE-2025-24480

CVE-2025-24480 is a critical remote code execution vulnerability affecting Rockwell Automation FactoryTalk View ME versions prior to 15.0. According to the CISA CSAF advisory, the issue stems from insufficient input sanitation and could allow a remote attacker to run commands or code as a highly privileged user. Rockwell Automation and CISA list version 15.0 or vendor-provided patches as the primary remed [truncated]

HIGH Rockwell Automation CVE published 2025-01-28

CVE-2025-24479

CVE-2025-24479 is a high-severity local code execution issue in Rockwell Automation FactoryTalk View ME versions prior to 15.0, published by CISA on 2025-01-28. The advisory says the problem stems from a default Windows setting and can let a local user reach a command prompt as a higher-privileged user. Rockwell’s guidance is to upgrade to V15.0 or apply the listed patches, and to reduce exposure by limit [truncated]

MEDIUM Rockwell Automation CVE published 2025-01-28

CVE-2025-0659

Rockwell Automation DataMosaix Private Cloud contains a path traversal vulnerability that can let an authenticated administrator overwrite files outside the intended directory. According to the CISA advisory, the issue affects DataEdgePlatform DataMosaix Private Cloud versions up to 7.11 and is addressed in v7.11.01. The reported impact is primarily integrity-related, including the potential to overwrite [truncated]

CRITICAL Rockwell Automation CVE published 2024-12-17

CVE-2024-12373

A critical buffer overflow vulnerability in Rockwell Automation PowerMonitor 1000 series devices enables remote denial-of-service attacks. The vulnerability, published December 17, 2024, affects fourteen product variants running firmware versions prior to 4.020. Rockwell Automation has released corrected firmware and recommends immediate upgrade.

CRITICAL Rockwell Automation CVE published 2024-12-17

CVE-2024-12372

A critical heap corruption vulnerability in Rockwell Automation PowerMonitor 1000 devices enables remote attackers to execute code or cause denial-of-service conditions. The vulnerability stems from improper memory handling that corrupts heap memory, potentially compromising system integrity. CISA published this advisory on December 17, 2024, with a CVSS 3.1 score of 9.8 (Critical). Fourteen product varia [truncated]

CRITICAL Rockwell Automation CVE published 2024-12-17

CVE-2024-12371

A critical device takeover vulnerability in Rockwell Automation PowerMonitor 1000 series devices allows unauthenticated attackers to create a Policyholder user—the most privileged account—via API calls. This grants complete device control including administrative user creation and factory reset capabilities. The vulnerability affects 14 product variants running firmware versions prior to 4.020. CISA publi [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2025-6377

A remote code execution vulnerability exists in Rockwell Automation Arena simulation software versions 16.20.08 and earlier. The flaw stems from an out-of-bounds write condition when processing DOE (Design of Experiments) files, which can be exploited to execute arbitrary code. Exploitation requires user interaction—a legitimate user must open a maliciously crafted DOE file. The vulnerability was disclose [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2025-6376

A remote code execution vulnerability exists in Rockwell Automation Arena simulation software versions 16.20.08 and earlier. The flaw stems from an out-of-bounds write condition when processing DOE (Design of Experiments) files, which could allow arbitrary code execution if a user opens a maliciously crafted file. This vulnerability requires user interaction for exploitation—a legitimate user must execute [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-12672

A third-party vulnerability in Rockwell Automation Arena 32-bit (versions ≤16.20.07) allows memory corruption via malformed DOE files, enabling arbitrary code execution under local user interaction. The vulnerability was disclosed by CISA on December 10, 2024, with an advisory update (Update B) published February 3, 2026. Rockwell Automation has released version 16.20.09 to address this issue.

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-12175

A use-after-free vulnerability in Rockwell Automation Arena simulation software enables arbitrary code execution when a user opens a maliciously crafted DOE file. The flaw stems from improper memory management where freed resources are reused, allowing an attacker to hijack execution flow. Exploitation requires local access and user interaction—specifically, a legitimate user must execute the crafted file [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-12130

CVE-2024-12130 is a high-severity out-of-bounds read vulnerability in Rockwell Automation Arena simulation software, published by CISA on December 10, 2024, with an advisory update (Update B) issued February 3, 2026. The flaw exists in Arena versions 16.20.05 and earlier, where a crafted DOE (Design of Experiments) file can force the application to read beyond allocated memory boundaries. Successful explo [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-11364

CVE-2024-11364 is a high-severity uninitialized variable vulnerability in Rockwell Automation Arena 32-bit simulation software (versions ≤16.20.06). The flaw allows arbitrary code execution when a user opens a maliciously crafted DOE file that forces the application to access an uninitialized variable. The vulnerability requires local access and user interaction, with a CVSS 3.1 score of 7.8. CISA publish [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-11158

CVE-2024-11158 is a high-severity uninitialized variable vulnerability in Rockwell Automation Arena simulation software, published 2024-12-10 and last modified 2026-02-03. The flaw exists in Arena versions 16.20.00 and earlier, where a crafted DOE (Design of Experiments) file can force the software to access a variable before initialization, leading to arbitrary code execution. Exploitation requires local [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-11156

A high-severity out-of-bounds write vulnerability in Rockwell Automation Arena simulation software allows arbitrary code execution when a user opens a maliciously crafted DOE file. The vulnerability was disclosed by CISA on December 10, 2024, with the advisory subsequently updated twice—most recently on February 3, 2026—to add related CVEs and refine affected product listings. The flaw stems from improper [truncated]

HIGH Rockwell Automation CVE published 2024-12-10

CVE-2024-11155

A use-after-free vulnerability in Rockwell Automation Arena simulation software allows arbitrary code execution when a user opens a maliciously crafted DOE file. The flaw exists in Arena versions 16.20.00 and earlier. An attacker can exploit this by crafting a DOE file that forces the software to reuse a freed resource, leading to code execution in the context of the legitimate user who opens the file. Th [truncated]

HIGH Rockwell Automation CVE published 2024-11-14

CVE-2024-6068

CVE-2024-6068 is a memory corruption vulnerability in Rockwell Automation Arena Input Analyzer version v16.20.00 (as included in Arena v16.20.03). The flaw occurs when parsing DFT files and can be exploited by local threat actors to disclose information and execute arbitrary code. Exploitation requires a legitimate user to open a malicious DFT file. The vulnerability was published on November 14, 2024, wi [truncated]

HIGH Rockwell Automation CVE published 2024-11-14

CVE-2024-10945

A local privilege escalation vulnerability in Rockwell Automation FactoryTalk Updater components allows low-privileged attackers to replace files during update operations due to insufficient security checks before installation. The vulnerability affects the Web Client (versions 4.00.00 to 4.20.00), Client (versions below 4.20.00), and Agent (versions below 4.20.00). Published by CISA on November 14, 2024, [truncated]

HIGH Rockwell Automation CVE published 2024-11-14

CVE-2024-10944

A high-severity remote code execution vulnerability in Rockwell Automation FactoryTalk Updater components, published 2024-11-14 and updated 2024-11-18. The flaw stems from improper input validation that could allow deployment of a malicious update agent when an attacker possesses high-level permissions. While the CVSS 3.1 score of 8.4 reflects significant impact potential, the attack requires high privile [truncated]

CRITICAL Rockwell Automation CVE published 2024-11-14

CVE-2024-10943

A critical authentication bypass vulnerability in Rockwell Automation FactoryTalk Updater components allows threat actors to impersonate users by exploiting shared secrets across accounts. The vulnerability stems from improper credential management where authentication secrets are not uniquely assigned per user account, enabling impersonation attacks when combined with enumerated supplementary authenticat [truncated]

HIGH Rockwell Automation CVE published 2024-11-12

CVE-2024-37365

A remote code execution vulnerability in Rockwell Automation FactoryTalk View ME allows users to save projects within the public directory, enabling any local user to modify or delete files. A malicious actor could escalate privileges by altering macros to execute arbitrary code. The vulnerability stems from default folder privileges that grant excessive permissions to the INTERACTIVE group. Rockwell Auto [truncated]

HIGH Rockwell Automation CVE published 2024-10-31

CVE-2024-10387

A denial-of-service vulnerability in Rockwell Automation FactoryTalk ThinManager allows network-based threat actors to crash the service by sending crafted messages. The vulnerability affects multiple ThinManager versions from 11.2.0 through 14.0.0. Rockwell Automation has released patches for all affected versions.

CRITICAL Rockwell Automation CVE published 2024-10-31

CVE-2024-10386

A critical authentication vulnerability in Rockwell Automation FactoryTalk ThinManager allows unauthenticated network attackers to send crafted messages that may result in database manipulation. The flaw affects multiple ThinManager versions from 11.2.0 through 14.0.0. Rockwell Automation has released patches for all affected versions.

MEDIUM Rockwell Automation CVE published 2024-10-10

CVE-2024-9412

An improper authorization vulnerability in Rockwell Automation Verve Asset Manager versions prior to 1.38 could allow unauthorized users to sign in and access data they no longer have permission to view. The vulnerability occurs when all role mappings are removed—typically through accidental or unexpected administrator action—leaving the system without proper access controls. While this configuration stat [truncated]

HIGH Rockwell Automation CVE published 2024-10-10

CVE-2024-9124

CVE-2024-9124 is a high-severity denial-of-service vulnerability affecting Rockwell Automation PowerFlex 6000T drives. Published on October 10, 2024, this issue allows an attacker to render the device unavailable by overloading it with requests. Recovery may require a manual power cycle if the device fails to re-establish connectivity after the request flood ceases. The vulnerability carries a CVSS 3.1 sc [truncated]

HIGH Rockwell Automation CVE published 2024-10-10

CVE-2024-8626

A memory leak vulnerability in Rockwell Automation Logix controllers enables unauthenticated remote denial-of-service. Attackers can trigger full device unavailability requiring physical power cycling by performing repeated actions on specific product webpages. The vulnerability affects six product lines across CompactLogix, GuardLogix, ControlLogix, and 1756-EN4TR communication modules. CISA published ad [truncated]