Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2970▼ 106 respecto a la semana anterior
Críticas / altas1447▲ 86 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
–

91 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaCrítica (9.8)5.7%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.9%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.5%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
ModificadaCrítica (9.8)3.8%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
ModificadaCrítica (9.8)3.2%—Rockwellautomation Factorytalk Assetcentre23/3/202217/6/2026
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk…
ModificadaAlta (7.8)0.16%—Rockwellautomation Factorytalk View24/2/202217/6/2026
The DeskLock tool provided with FactoryTalk View SE uses a weak encryption algorithm that may allow a local, authenticated attacker to decipher user credentials, including the Windows user or Windows DeskLock passwords. If the compromised user has an administrative account, an attacker could gain full access to the…
ModificadaMedia (5.5)0.27%—Rockwellautomation Factorytalk View24/2/202217/6/2026
Due to usernames/passwords being stored in plaintext in Random Access Memory (RAM), a local, authenticated attacker could gain access to certain credentials, including Windows Logon credentials.
ModificadaAlta (7.1)0.34%—Rockwellautomation Factorytalk Services Platform24/2/202217/6/2026
A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service condition and allow the attacker to arbitrarily read any local file via system-level services.
ModificadaCrítica (10)4.1%—Rockwellautomation Factorytalk Services Platform18/3/202117/6/2026
In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user password from being hashed properly.
AnalizadaCrítica (9.8)64%⚠ Explotación activa💥 PoCRockwellautomation Factorytalk Services PlatformRockwellautomation Rslogix 5000Rockwellautomation Studio 5000 Logix Designer3/3/202117/6/2026
Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769, 5370, 5380, 5480: ControlLogix 5550, 5560, 5570, 5580; DriveLogix 5560, 5730, 1794-L34; Compact…
ModificadaAlta (7.5)34%—Rockwellautomation Factorytalk Diagnostics29/12/202017/6/2026
An unauthenticated remote attacker can send data to RsvcHost.exe listening on TCP port 5241 to add entries in the FactoryTalk Diagnostics event log. The attacker can specify long fields in the log entry, which can cause an unhandled exception in wcscpy_s() if a local user opens FactoryTalk Diagnostics Viewer…
ModificadaMedia (5.5)4.8%—Rockwellautomation Factorytalk Linx29/12/202017/6/2026
An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
ModificadaAlta (7.5)39%—Rockwellautomation Factorytalk Linx29/12/202017/6/2026
An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx…
ModificadaAlta (7.5)25%—Rockwellautomation Factorytalk Linx29/12/202017/6/2026
An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected.
ModificadaAlta (7.5)3.9%—Rockwellautomation Factorytalk Linx26/11/202017/6/2026
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address…
ModificadaAlta (7.5)1.9%—Rockwellautomation Factorytalk Linx26/11/202017/6/2026
A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device.
ModificadaCrítica (9.8)6.8%—Rockwellautomation Factorytalk Linx26/11/202017/6/2026
A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution.
ModificadaAlta (7.8)0.60%—Rockwellautomation Factorytalk View20/7/202017/6/2026
In all versions of FactoryTalk View SE, after bypassing memory corruption mechanisms found in the operating system, a local, authenticated attacker may corrupt the associated memory space allowing for arbitrary code execution. Rockwell Automation recommends applying patch 1126290. Before installing this patch, the…
ModificadaAlta (8.1)53%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handlers do not enforce appropriate permissions. Rockwell Automation recommends enabling built in security features found within FactoryTalk…
ModificadaMedia (4.3)53%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this information for reconnaissance efforts. Rockwell Automation recommends enabling built in security features found within FactoryTalk View SE. Users…
ModificadaAlta (7.8)47%💥 ExploitRockwellautomation Factorytalk View20/7/202017/6/2026
All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file on a remote endpoint that may result in remote code execution (RCE). Rockwell Automation recommends applying patch 1126289. Before…
ModificadaAlta (8.8)1.1%—Rockwellautomation Factorytalk Services Platform23/6/202017/6/2026
In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute remote COM objects with elevated privileges.
ModificadaAlta (7.5)1.8%—Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic15/6/202017/6/2026
FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000…
Orbitaley — Vulnerabilidades