rockwellautomation security advisories
10 threat alerts tracking vulnerabilities and security advisories that affect rockwellautomation products.
Vulnios monitors rockwellautomation CVE feeds, vendor advisories, CISA KEV listings, and exploit-prediction data continuously. Each alert below is enriched with severity, exploitation status, affected products, and a remediation path. Use this page to scan recent rockwellautomation security news in one place, or click into an individual alert for full detail.
Critical Vulnerability: CVE-2012-6437 — rockwellautomation — controllogix_controllers, guardlogix_controllers
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Su
criticalCVE-2012-6437Critical Vulnerability: CVE-2015-6490 — rockwellautomation — micrologix_1100_firmware, micrologix_1400_firmware
Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors
criticalCVE-2015-6490Critical Vulnerability: CVE-2020-6990 — rockwellautomation — micrologix_1400_a_firmware, micrologix_1400_b_firmware
Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic
criticalCVE-2020-6990Critical Vulnerability: CVE-2016-4522 — rockwellautomation — factorytalk_energrymetrix
SQL injection vulnerability in Rockwell Automation FactoryTalk EnergyMetrix before 2.20.00 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.
criticalCVE-2016-4522Critical Vulnerability: CVE-2016-0868 — rockwellautomation — ab_micrologix_controller, 1763-l16awa_series_a
Stack-based buffer overflow on Rockwell Automation Allen-Bradley MicroLogix 1100 devices A through 15.000 and B before 15.002 allows remote attackers to execute arbitrary code via a crafted web reques
criticalCVE-2016-0868Critical Vulnerability: CVE-2017-7899 — rockwellautomation — 1763-l16awa_series_a, 1763-l16awa_series_b
An Information Exposure issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 1763-L16
criticalCVE-2017-7899Critical Vulnerability: CVE-2017-7902 — rockwellautomation — 1763-l16awa_series_a, 1763-l16awa_series_b
A "Reusing a Nonce, Key Pair in Encryption" issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prio
criticalCVE-2017-7902Critical Vulnerability: CVE-2017-7903 — rockwellautomation — 1763-l16awa_series_a, 1763-l16awa_series_b
A Weak Password Requirements issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Version 16.00 and prior versions; 176
criticalCVE-2017-7903Critical Vulnerability: CVE-2017-7898 — rockwellautomation — 1763-l16awa_series_a, 1763-l16awa_series_b
An Improper Restriction of Excessive Authentication Attempts issue was discovered in Rockwell Automation Allen-Bradley MicroLogix 1100 programmable-logic controllers 1763-L16AWA, Series A and B, Versi
criticalCVE-2017-7898Critical Vulnerability: CVE-2016-9343 — rockwellautomation — softlogix_5800_controller_firmware, softlogix_5800_controller
An issue was discovered in Rockwell Automation Logix5000 Programmable Automation Controller FRN 16.00 through 21.00 (excluding all firmware versions prior to FRN 16.00, which are not affected). By sen
criticalCVE-2016-9343
Track rockwellautomation exposure across your environment
Vulnios automatically cross-references your asset inventory against new rockwellautomation CVEs and surfaces only what affects you. No more sifting manually — actionable findings only.
Start a free scan