Show filters
40 Total Results
Displaying 31-40 of 40
Sort by:
Attacker Value
Unknown

CVE-2024-7507

Disclosure Date: August 14, 2024 (last updated August 15, 2024)
CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
0
Attacker Value
Unknown

CVE-2024-6078

Disclosure Date: August 14, 2024 (last updated August 15, 2024)
CVE-2024-6078 IMPACT An improper authentication vulnerability exists in the affected product, which could allow a malicious user to generate cookies for any user ID without the use of a username or password. If exploited, a malicious user could take over the account of a legitimate user. The malicious user would be able to view and modify data stored in the cloud.
0
Attacker Value
Unknown

CVE-2024-7567

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
A denial-of-service vulnerability exists via the CIP/Modbus port in the Rockwell Automation Micro850/870 (2080 -L50E/2080 -L70E). If exploited, the CIP/Modbus communication may be disrupted for short duration.
0
Attacker Value
Unknown

CVE-2024-6079

Disclosure Date: August 13, 2024 (last updated August 14, 2024)
A vulnerability exists in the Rockwell Automation Emulate3D™, which could be leveraged to execute a DLL Hijacking attack. The application loads shared libraries, which are readable and writable by any user. If exploited, a malicious user could leverage a malicious dll and perform a remote code execution attack.
0
Attacker Value
Unknown

CVE-2024-6242

Disclosure Date: August 01, 2024 (last updated August 02, 2024)
A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a threat actor could potentially execute CIP commands that modify user projects and/or device configuration on a Logix controller in the chassis.
0
Attacker Value
Unknown

CVE-2024-5659

Disclosure Date: June 14, 2024 (last updated June 15, 2024)
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
0
Attacker Value
Unknown

CVE-2024-3640

Disclosure Date: May 16, 2024 (last updated May 17, 2024)
An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a System user. A threat actor needs admin privileges to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-3493

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will become unavailable and require a manual restart to recover it. Additionally, an MNRF could result in a loss of view and/or control of connected devices.
0
Attacker Value
Unknown

CVE-2024-2424

Disclosure Date: April 15, 2024 (last updated April 16, 2024)
An input validation vulnerability exists in the Rockwell Automation 5015-AENFTXT that causes the secondary adapter to result in a major nonrecoverable fault (MNRF) when malicious input is entered. If exploited, the availability of the device will be impacted, and a manual restart is required. Additionally, a malformed PTP packet is needed to exploit this vulnerability.
0
Attacker Value
Unknown

CVE-2024-21914

Disclosure Date: March 25, 2024 (last updated April 02, 2024)
A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product.
0