Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
91 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Baja (1.8) | 0.18% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 16/7/2024 | 17/6/2026 | An exposure of sensitive information vulnerability exists in the Rockwell Automation FactoryTalk® System Service. A malicious user could exploit this vulnerability by starting a back-up or restore process, which temporarily exposes private keys, passwords, pre-shared keys, and database folders when they are… | |
| Modificada | Media (6) | 0.30% | — | Rockwellautomation Factorytalk Policy Manager | 16/7/2024 | 17/6/2026 | The v6.40 release of Rockwell Automation FactoryTalk® Policy Manager CVE-2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and CVE-2022-1161 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1585.html by implementing CIP… | |
| Analizada | Alta (8.5) | 0.33% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A privilege escalation vulnerability exists in the affected product. The vulnerability allows low-privilege users to edit scripts, bypassing Access Control Lists, and potentially gaining further access within the system. | |
| Analizada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. Due to the lack of proper authentication, this action is allowed without proper authentication… | |
| Modificada | Alta (8.2) | 0.50% | — | Rockwellautomation Factorytalk View | 14/6/2024 | 17/6/2026 | A user authentication vulnerability exists in the Rockwell Automation FactoryTalk® View SE v12. The vulnerability allows a user from a remote system with FTView to send a packet to the customer’s server to view an HMI project. This action is allowed without proper authentication verification. | |
| Analizada | Alta (8.8) | 0.65% | — | Rockwellautomation Factorytalk View | 16/5/2024 | 17/6/2026 | A vulnerability exists in the Rockwell Automation FactoryTalk® View SE Datalog function that could allow a threat actor to inject a malicious SQL statement if the SQL database has no authentication in place or if legitimate credentials were stolen. If exploited, the attack could result in information exposure,… | |
| Aplazada | Alta (7) | 0.27% | 💥 PoC | Rockwellautomation Factorytalk Remote AccessAI | 16/5/2024 | 17/6/2026 | An unquoted executable path exists in the Rockwell Automation FactoryTalk® Remote Access™ possibly resulting in remote code execution if exploited. While running the FTRA installer package, the executable path is not properly quoted, which could allow a threat actor to enter a malicious executable and run it as a… | |
| Analizada | Media (5.3) | 0.66% | — | Rockwellautomation Factorytalk View | 25/3/2024 | 17/6/2026 | A vulnerability exists in the affected product that allows a malicious user to restart the Rockwell Automation PanelView™ Plus 7 terminal remotely without security protections. If the vulnerability is exploited, it could lead to the loss of view or control of the PanelView™ product. | |
| Analizada | Alta (8.8) | 0.99% | — | Rockwellautomation Factorytalk Services Platform | 16/2/2024 | 17/6/2026 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and receive FTSP Administrator Group privileges. A threat actor could potentially read and modify sensitive… | |
| Modificada | Crítica (9.1) | 0.86% | — | Rockwellautomation Factorytalk Services Platform | 31/1/2024 | 17/6/2026 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of digital signing between the FTSP service token and directory. If exploited, a malicious user could… | |
| Modificada | Alta (8.1) | 2.7% | — | Rockwellautomation Factorytalk Services Platform | 27/10/2023 | 17/6/2026 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into FactoryTalk® Services Platform . This vulnerability can only be exploited if the authorized user… | |
| Modificada | Alta (7.5) | 0.90% | — | Rockwellautomation Factorytalk View | 27/10/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Site Edition insufficiently validates user input, which could potentially allow threat actors to send malicious data bringing the product offline. If exploited, the product would become unavailable and require a restart to recover resulting in a denial-of-service condition. | |
| Modificada | Crítica (9.1) | 9.6% | — | Rockwellautomation Factorytalk Linx | 13/10/2023 | 17/6/2026 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes… | |
| Modificada | Crítica (9.8) | 17% | — | Rockwellautomation Factorytalk View | 12/9/2023 | 17/6/2026 | Rockwell Automation FactoryTalk View Machine Edition on the PanelView Plus, improperly verifies user’s input, which allows unauthenticated attacker to achieve remote code executed via crafted malicious packets. The device has the functionality, through a CIP class, to execute exported functions from libraries. There… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Transaction Manager | 13/6/2023 | 17/6/2026 | A denial-of-service vulnerability exists in Rockwell Automation FactoryTalk Transaction Manager. This vulnerability can be exploited by sending a modified packet to port 400. If exploited, the application could potentially crash or experience a high CPU or memory usage condition, causing intermittent application… | |
| Modificada | Media (4.7) | 0.38% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | The underlying feedback mechanism of Rockwell Automation's FactoryTalk System Services that transfers the FactoryTalk Policy Manager rules to relevant devices on the network does not verify that the origin of the communication is from a legitimate local client device. This may allow a threat actor to craft a malicious… | |
| Modificada | Media (5) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services does not verify that a backup configuration archive is password protected. Improper authorization in FTSSBackupRestore.exe may lead to the loading of malicious configuration archives. This vulnerability may allow a local, authenticated non-admin user to craft a… | |
| Modificada | Alta (8.2) | 0.20% | — | Rockwellautomation Factorytalk Policy ManagerRockwellautomation Factorytalk System Services | 13/6/2023 | 17/6/2026 | Rockwell Automation's FactoryTalk System Services uses a hard-coded cryptographic key to generate administrator cookies. Hard-coded cryptographic key may lead to privilege escalation. This vulnerability may allow a local, authenticated non-admin user to generate an invalid administrator cookie giving them… | |
| Modificada | Alta (8.8) | 0.38% | — | Rockwellautomation Factorytalk Vantagepoint | 11/5/2023 | 17/6/2026 | A cross site request forgery vulnerability exists in Rockwell Automation's FactoryTalk Vantagepoint. This vulnerability can be exploited in two ways. If an attacker sends a malicious link to a computer that is on the same domain as the FactoryTalk Vantagepoint server and a user clicks the link, the attacker could… | |
| Modificada | Alta (7.5) | 1.2% | — | Rockwellautomation Factorytalk Alarms AND Events | 27/10/2022 | 17/6/2026 | An unauthenticated attacker with network access to a victim's Rockwell Automation FactoryTalk Alarm and Events service could open a connection, causing the service to fault and become unavailable. The affected port could be used as a server ping port and uses messages structured with XML. | |
| Modificada | Alta (8.8) | 3.5% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an input validation vulnerability. The FactoryTalk VantagePoint SQL Server lacks input validation when users enter SQL statements to retrieve information from the back-end database. If successfully exploited, this could… | |
| Modificada | Alta (8.8) | 1.4% | — | Rockwellautomation Factorytalk Vantagepoint | 17/10/2022 | 17/6/2026 | Rockwell Automation FactoryTalk VantagePoint versions 8.0, 8.10, 8.20, 8.30, 8.31 are vulnerable to an improper access control vulnerability. The FactoryTalk VantagePoint SQL Server account could allow a malicious user with read-only privileges to execute SQL statements in the back-end database. If successfully… | |
| Modificada | Alta (8.8) | 2.4% | — | Rockwellautomation Factorytalk Services Platform | 1/4/2022 | 17/6/2026 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk Security policies based on the computer name. If successfully exploited, this may allow an attacker to have… | |
| Modificada | Crítica (9.8) | 4.1% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. | |
| Modificada | Alta (7.5) | 1.6% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. |