Show filters
273 Total Results
Displaying 1-10 of 273
Sort by:
Attacker Value
Unknown

CVE-2024-12175

Disclosure Date: December 19, 2024 (last updated January 13, 2025)
Another “use after free” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to use a resource that was already used. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Attacker Value
Unknown

CVE-2024-11364

Disclosure Date: December 19, 2024 (last updated January 22, 2025)
Another “uninitialized variable” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to access a variable prior to it being initialized. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Attacker Value
Unknown

CVE-2024-11157

Disclosure Date: December 19, 2024 (last updated January 22, 2025)
A third-party vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Attacker Value
Unknown

CVE-2024-12130

Disclosure Date: December 05, 2024 (last updated December 18, 2024)
An “out of bounds read” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to craft a DOE file and force the software to read beyond the boundaries of an allocated memory. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Attacker Value
Unknown

CVE-2024-11156

Disclosure Date: December 05, 2024 (last updated December 18, 2024)
An “out of bounds write” code execution vulnerability exists in the Rockwell Automation Arena® that could allow a threat actor to write beyond the boundaries of allocated memory in a DOE file. If exploited, a threat actor could leverage this vulnerability to execute arbitrary code. To exploit this vulnerability, a legitimate user must execute the malicious code crafted by the threat actor.
Attacker Value
Unknown

CVE-2024-10387

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
CVE-2024-10387 IMPACT A Denial-of-Service vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in Denial-of-Service.
Attacker Value
Unknown

CVE-2024-10386

Disclosure Date: October 25, 2024 (last updated November 06, 2024)
CVE-2024-10386 IMPACT An authentication vulnerability exists in the affected product. The vulnerability could allow a threat actor with network access to send crafted messages to the device, potentially resulting in database manipulation.
Attacker Value
Unknown

CVE-2024-6207

Disclosure Date: October 14, 2024 (last updated October 22, 2024)
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html  and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To recover the controllers, a download is required which ends any process that the controller is running.
Attacker Value
Unknown

CVE-2024-7961

Disclosure Date: September 12, 2024 (last updated September 19, 2024)
A path traversal vulnerability exists in the Rockwell Automation affected product. If exploited, the threat actor could upload arbitrary files to the server that could result in a remote code execution.
Attacker Value
Unknown

CVE-2024-7960

Disclosure Date: September 12, 2024 (last updated September 19, 2024)
The Rockwell Automation affected product contains a vulnerability that allows a threat actor to view sensitive information and change settings. The vulnerability exists due to having an incorrect privilege matrix that allows users to have access to functions they should not.