PatchSiren

Rockwell Automation CVE debriefs · Page 4

These pages are published after PatchSiren validates generated defensive summaries against stored public CVE and source evidence.

HIGH Rockwell Automation CVE published 2024-10-10

CVE-2024-7953

A vulnerability in Rockwell Automation DataMosaix Private Cloud allows an authenticated threat actor to create a project and become its administrator, enabling unauthorized creation, modification, and deletion of project data. The issue stems from improper authorization controls that fail to restrict project creation privileges. This vulnerability was disclosed by CISA on October 10, 2024, with a CVSS 3.1 [truncated]

HIGH Rockwell Automation CVE published 2024-10-10

CVE-2024-7952

A data exposure vulnerability in Rockwell Automation DataMosaix Private Cloud allows unauthenticated access to customer data via hardcoded links to JSON files. The vulnerability exists in versions 7.07 and earlier, with a fix available in version 7.09. The issue was disclosed by CISA on October 10, 2024.

HIGH Rockwell Automation CVE published 2024-10-10

CVE-2024-6207

A denial-of-service vulnerability in Rockwell Automation ControlLogix controllers causes a Major Non-Recoverable Fault (MNRF) when processing malformed CIP requests. Exploitation requires chaining with CVE-2021-22681 to send crafted CIP messages, resulting in controller crash and termination of all running processes. Recovery requires a full controller download, disrupting operational technology environments.

CRITICAL Rockwell Automation CVE published 2024-10-10

CVE-2019-9893

This CVE describes a vulnerability in libseccomp versions 2.4.0 and earlier, which is utilized by Rockwell Automation DataMosaix Private Cloud versions 7.07 and earlier. The flaw involves incorrect generation of 64-bit syscall argument comparisons when using arithmetic operators (LT, GT, LE, GE), which could allow bypassing seccomp filters and potential privilege escalation. If exploited, this vulnerabili [truncated]

HIGH Rockwell Automation CVE published 2024-09-19

CVE-2024-7847

A vulnerability in Rockwell Automation RSLogix 5 and RSLogix 500 allows malicious VBA scripts embedded in project files to execute automatically upon opening, enabling remote code execution. The issue stems from a legitimate feature that permits VBA scripts to run without user intervention when a project file is opened. An attacker could craft a malicious RSP or RSS project file containing embedded VBA co [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-8533

A privilege escalation vulnerability in Rockwell Automation OptixPanel products allows credential exfiltration through improper default file permissions. The vulnerability affects three product lines: 2800C OptixPanel Compact (version 4.0.0.325), 2800S OptixPanel Standard (version 4.0.0.350), and Embedded Edge Compute Module (version 4.0.0.347). The issue was disclosed on September 12, 2024, with a CVSS 3 [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-7961

A path traversal vulnerability in Rockwell Automation Pavilion8 versions prior to V5.20 allows authenticated attackers with high privileges to upload arbitrary files to the server, potentially resulting in remote code execution. The vulnerability was disclosed by CISA on September 12, 2024, with a CVSS 3.1 score of 7.2 (HIGH). The attack vector is network-based with low attack complexity, requiring high p [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-7960

CVE-2024-7960 is a HIGH severity vulnerability (CVSS 7.6) in Rockwell Automation Pavilion8, published September 12, 2024. The vulnerability stems from an incorrect privilege matrix that allows users to access functions beyond their authorized scope, enabling threat actors to view sensitive information and modify settings. The affected product is Pavilion8 versions prior to V5.20. Rockwell Automation has r [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-6077

A denial-of-service vulnerability exists in Rockwell Automation ControlLogix/GuardLogix 5580 and CompactLogix/Compact GuardLogix 5380 controllers when specially crafted packets are sent to the CIP security object. Successful exploitation renders the device unavailable and requires a factory reset to recover. The vulnerability was disclosed on September 12, 2024, with a CVSS 3.1 score of 7.5 (HIGH). Rockwe [truncated]

MEDIUM Rockwell Automation CVE published 2024-09-12

CVE-2024-45826

A path traversal and remote code execution vulnerability exists in Rockwell Automation ThinManager due to improper input validation when processing crafted POST requests. Successful exploitation allows an authenticated attacker with high privileges to install executable files on affected systems. The vulnerability was disclosed by CISA on September 12, 2024, with patches available for affected versions.

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-45825

A denial-of-service vulnerability exists in Rockwell Automation 5015-U8IHFT devices running firmware version 1.012 and prior. The vulnerability can be triggered when a malformed Common Industrial Protocol (CIP) packet is sent over the network to the affected device, resulting in a major nonrecoverable fault that causes denial-of-service. This vulnerability has a CVSS 3.1 score of 7.5 (HIGH severity) with [truncated]

CRITICAL Rockwell Automation CVE published 2024-09-12

CVE-2024-45824

A critical remote code execution vulnerability exists in Rockwell Automation FactoryTalk View Site Edition versions 12.0, 13.0, and 14.0. The vulnerability, published on September 12, 2024, achieves full unauthenticated remote code execution when chained with path traversal, command injection, and cross-site scripting vulnerabilities. The CVSS 3.1 score of 9.8 reflects network attack vector, low attack co [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2024-45823

An authentication bypass vulnerability in Rockwell Automation FactoryTalk Batch View (versions ≤2.01.00) allows threat actors to impersonate users by exploiting shared secrets across accounts. The vulnerability requires the attacker to enumerate additional authentication information to achieve impersonation. The CVSS 3.1 score of 8.1 (High) reflects significant impact potential with network attack vector, [truncated]

HIGH Rockwell Automation CVE published 2024-09-12

CVE-2023-31102

CVE-2023-31102 is a high-severity vulnerability in Rockwell Automation AADvance Trusted SIS Workstation software, published on September 12, 2024. The vulnerability stems from an integer underflow in 7-Zip's handling of 7Z archive files, which can lead to arbitrary code execution when a user opens a malicious archive. The CVSS 3.1 score of 7.8 reflects high impacts to confidentiality, integrity, and avail [truncated]

HIGH Rockwell Automation CVE published 2024-09-10

CVE-2024-6436

A high-severity input validation vulnerability in Rockwell Automation SequenceManager allows unauthenticated remote attackers to cause denial-of-service conditions by sending malformed network packets. Successful exploitation renders the device unresponsive, requiring manual restart for recovery. While the underlying equipment sequences continue executing uninterrupted, operators lose visibility and contr [truncated]

CRITICAL Rockwell Automation CVE published 2024-08-29

CVE-2024-7988

A critical remote code execution vulnerability in Rockwell Automation ThinManager ThinServer allows unauthenticated threat actors to execute arbitrary code with System privileges. The vulnerability stems from insufficient input validation that enables arbitrary file overwrite operations. Affected versions span multiple release branches from 11.1.0 through 13.2.0. Rockwell Automation has released patched v [truncated]

HIGH Rockwell Automation CVE published 2024-08-29

CVE-2024-7987

A remote code execution vulnerability in Rockwell Automation ThinManager ThinServer allows a threat actor to execute arbitrary code with System privileges by abusing the ThinServer service to create a junction and upload arbitrary files. The vulnerability was published on August 29, 2024, with a CVSS 3.1 score of 7.8 (HIGH). Multiple versions across the 11.x, 12.x, and 13.x release lines are affected. Roc [truncated]

MEDIUM Rockwell Automation CVE published 2024-08-29

CVE-2024-7986

A vulnerability in Rockwell Automation ThinManager ThinServer allows local attackers to disclose sensitive information by abusing the ThinServer service to read arbitrary files through directory junction manipulation. The flaw requires local access and low privileges, with no user interaction needed. Rockwell Automation has released patched versions across multiple release branches.

HIGH Rockwell Automation CVE published 2024-08-22

CVE-2024-6089

An input validation vulnerability in Rockwell Automation 5015 - AENFTXT (firmware version 2.011) allows an unauthenticated remote attacker to cause a major nonrecoverable fault on the secondary adapter by sending a manipulated PTP (Precision Time Protocol) packet. Successful exploitation results in a denial-of-service condition requiring a physical power cycle to recover the device. The vulnerability is r [truncated]

MEDIUM Rockwell Automation CVE published 2024-08-22

CVE-2024-6079

A DLL hijacking vulnerability in Rockwell Automation Emulate3D (version 17.00.00.13276) allows local attackers to execute arbitrary code by placing a malicious DLL in a location where the application loads shared libraries with overly permissive read/write access. The vulnerability requires local access, low privileges, and user interaction, with a CVSS 3.1 score of 6.7 (Medium severity). Rockwell Automat [truncated]

MEDIUM Rockwell Automation CVE published 2024-08-13

CVE-2024-7567

A denial-of-service vulnerability exists in Rockwell Automation Micro850/870 programmable logic controllers (PLCs) via the CIP/Modbus port. Successful exploitation can disrupt CIP/Modbus communications for a short duration. The vulnerability was disclosed on August 13, 2024, with a CVSS 3.1 score of 5.3 (Medium severity). Affected products are versions prior to v22.011. Rockwell Automation has released fi [truncated]

HIGH Rockwell Automation CVE published 2024-08-13

CVE-2024-7515

A denial-of-service vulnerability in Rockwell Automation industrial controllers allows unauthenticated remote attackers to trigger a major nonrecoverable fault by sending a malformed Precision Time Protocol (PTP) management packet. The vulnerability affects five product lines across the ControlLogix, GuardLogix, CompactLogix, and Compact GuardLogix families. Successful exploitation causes complete control [truncated]

HIGH Rockwell Automation CVE published 2024-08-13

CVE-2024-7513

A code execution vulnerability exists in Rockwell Automation FactoryTalk View Site Edition (SE) version 13.0 due to improper default file permissions on the HMI projects folder. The default configuration allows any user to edit or replace files in C:UsersPublicDocumentsRSView EnterpriseSEHMI projects, which are then executed by an account with elevated permissions. This local attack vector enables low-pri [truncated]

HIGH Rockwell Automation CVE published 2024-08-13

CVE-2024-7507

A denial-of-service vulnerability exists in Rockwell Automation ControlLogix, GuardLogix 5580, CompactLogix, and Compact GuardLogix 5380 controllers. The vulnerability occurs when a malformed Programmable Controller Communication Commands (PCCC) message is received, causing a fault in the controller. This vulnerability was published on August 13, 2024, and carries a CVSS 3.1 score of 7.5 (HIGH severity). [truncated]

CRITICAL Rockwell Automation CVE published 2024-08-13

CVE-2024-6078

A critical improper authentication vulnerability in Rockwell Automation DataMosaix Private Cloud allows unauthenticated attackers to forge session cookies for arbitrary user IDs, enabling complete account takeover and unauthorized data access.

HIGH Rockwell Automation CVE published 2024-08-13

CVE-2024-40620

A vulnerability exists in Rockwell Automation Pavilion8 due to lack of encryption of sensitive information. Data sent between the Console and the Dashboard is transmitted without encryption, which can be observed in proxy server logs, potentially impacting data confidentiality. The affected product is Pavilion8 versions 5.20 and later. Rockwell Automation has released product updates to address this vulnerability.

HIGH Rockwell Automation CVE published 2024-08-13

CVE-2024-40619

A denial-of-service vulnerability in Rockwell Automation GuardLogix 5580 and ControlLogix 5580 industrial controllers can be triggered by sending a malformed Common Industrial Protocol (CIP) packet over the network, resulting in a major nonrecoverable fault. The vulnerability, published on August 13, 2024, carries a CVSS 3.1 score of 7.5 (HIGH severity) due to its network attack vector, low attack complex [truncated]

MEDIUM Rockwell Automation CVE published 2024-08-13

CVE-2006-0743

A format string vulnerability in the log4net component of Rockwell Automation AADvance Standalone OPC-DA Server allows arbitrary code execution. The vulnerability affects versions 2.01.510 and later. Rockwell Automation has released version 2.02 to address this issue. The vulnerability is remotely exploitable with low attack complexity and requires no privileges or user interaction, though the CVSS v3.1 s [truncated]

HIGH Rockwell Automation CVE published 2024-08-01

CVE-2024-6242

A vulnerability in Rockwell Automation ControlLogix and GuardLogix 5580 controllers, along with multiple 1756-series Ethernet communication modules, allows a threat actor to bypass the Trusted Slot feature. Successful exploitation could enable unauthorized CIP command execution to modify user projects and device configurations on Logix controllers within a 1756 chassis. The vulnerability was disclosed on [truncated]

HIGH Rockwell Automation CVE published 2024-07-16

CVE-2024-6435

A privilege escalation vulnerability in Rockwell Automation Pavilion 8 allows authenticated users with basic privileges to access administrative functions, potentially enabling unauthorized user creation and sensitive data access.