Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas2856▼ 331 respecto a la semana anterior
Críticas / altas1383▼ 38 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)292▼ 217 respecto a la semana anterior
–

130 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
ModificadaMedia (6.5)4.3%—Rockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400 Firmware28/10/201517/6/2026
SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors.
ModificadaAlta (7.1)4.2%—Rockwellautomation AB Micrologix Controller3/10/201417/6/2026
The DNP3 feature on Rockwell Automation Allen-Bradley MicroLogix 1400 1766-Lxxxxx A FRN controllers 7 and earlier and 1400 1766-Lxxxxx B FRN controllers before 15.001 allows remote attackers to cause a denial of service (process disruption) via malformed packets over (1) an Ethernet network or (2) a serial line.
ModificadaMedia (6.9)0.56%—Rockwellautomation Rslogix 5000 Design AND Configuration Software5/2/201417/6/2026
Rockwell Automation RSLogix 5000 7 through 20.01, and 21.0, does not properly implement password protection for .ACD files (aka project files), which allows local users to obtain sensitive information or modify data via unspecified vectors.
ModificadaAlta (7.5)36%—Rockwellautomation Ethernet/ip FirmwareRockwellautomation Compactlogix FirmwareRockwellautomation Flexlogix FirmwareRockwellautomation Flex I/O Ethernet/ip Firmware+824/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the product to reset, a DoS can occur. This situation could cause loss of availability and a disruption of communication with other connected…
ModificadaMedia (5)57%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this vulnerability could cause loss of confidentiality. Rockwell Automation EtherNet/IP products; 1756-ENBT,…
ModificadaMedia (4.8)9.3%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server to view and alter product configuration and diagnostics information. Rockwell Automation EtherNet/IP…
ModificadaAlta (8.5)23%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network parameters, a DoS condition can occur. This situation could cause loss of availability and a disruption…
ModificadaAlta (7.5)27%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the NIC to crash. Successful exploitation of this vulnerability could cause loss of…
ModificadaCrítica (9.8)7.8%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful exploitation of this vulnerability could cause loss of availability, integrity, and confidentiality and a…
ModificadaAlta (7.5)27%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow and causes the CPU to crash. Successful exploitation of this vulnerability could cause loss of…
ModificadaAlta (7.5)33%—Rockwellautomation Controllogix ControllersRockwellautomation Guardlogix ControllersRockwellautomation MicrologixRockwellautomation Softlogix Controllers+1324/1/201316/6/2026
When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter a fault state, a DoS can occur. This situation could cause loss of availability and a disruption of…
ModificadaAlta (7.1)4.0%—Rockwellautomation AB Micrologix ControllerRockwellautomation Plc-5 ControllerRockwellautomation SLC 500 Controller8/12/201216/6/2026
Rockwell Automation Allen-Bradley MicroLogix controller 1100, 1200, 1400, and 1500; SLC 500 controller platform; and PLC-5 controller platform, when Static status is not enabled, allow remote attackers to cause a denial of service via messages that trigger modification of status bits.
ModificadaMedia (5)3.5%—Rockwellautomation FactorytalkRockwellautomation Rslogix 50002/4/201216/6/2026
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 allows remote attackers to cause a denial of service (out-of-bounds read) via a crafted packet.
ModificadaMedia (5)10%💥 ExploitRockwellautomation FactorytalkRockwellautomation Rslogix 50002/4/201216/6/2026
The FactoryTalk (FT) RNADiagReceiver service in Rockwell Automation Allen-Bradley FactoryTalk CPR9 through SR5 and RSLogix 5000 17 through 20 does not properly handle the return value from an unspecified function, which allows remote attackers to cause a denial of service (service outage) via a crafted packet.
ModificadaMedia (5)8.7%💥 ExploitRockwellautomation Rslogix16/9/201116/6/2026
RnaUtility.dll in RsvcHost.exe 2.30.0.23 in Rockwell RSLogix 19 and earlier allows remote attackers to cause a denial of service (crash) via a crafted rna packet with a long string to TCP port 4446 that triggers (1) "a memset zero overflow" or (2) an out-of-bounds read, related to improper handling of a 32-bit size…
ModificadaMedia (6.2)0.77%—Oracle Passlogix V-go Self-service Password Reset AND OEM7/2/201116/6/2026
Passlogix v-GO Self-Service Password Reset (SSPR) and OEM before 7.0A allows physically proximate attackers to execute arbitrary programs without authentication by triggering use of an invalid SSL certificate and using the Internet Explorer interface to navigate through the filesystem via a "Save As" dialog that is…
ModificadaAlta (10)5.9%—Rockwellautomation AB Micrologix Controller 1100Rockwellautomation AB Micrologix Controller 140019/1/201016/6/2026
Multiple unspecified vulnerabilities on the Rockwell Automation AB Micrologix 1100 and 1400 controllers allow remote attackers to obtain privileged access or cause a denial of service (halt) via unknown vectors.
ModificadaMedia (5)5.9%—Rockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
The web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to obtain "internal web page information" and "internal information about the module" via unspecified vectors. NOTE: this may overlap CVE-2002-1603.
ModificadaMedia (6.8)13%💥 PoCRockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
Open redirect vulnerability in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allows remote attackers to redirect users to arbitrary web sites and conduct phishing attacks via unspecified vectors.
ModificadaMedia (4.3)2.9%—Rockwellautomation Controllogix 1756-enbt/a Ethernet/ IP Bridge6/2/200916/6/2026
Multiple cross-site scripting (XSS) vulnerabilities in the web interface in the Rockwell Automation ControlLogix 1756-ENBT/A EtherNet/IP Bridge Module allow remote attackers to inject arbitrary web script or HTML via unspecified vectors.
ModificadaAlta (7.5)1.1%💥 ExploitVblogix Tutorial Script30/9/200816/6/2026
SQL injection vulnerability in main.php in vbLOGIX Tutorial Script 1.0 and earlier allows remote attackers to execute arbitrary SQL commands via the cat_id parameter in a list action.
ModificadaAlta (7.5)2.2%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SalesLogix 6.1 uses client-specified pathnames for writing certain files, which might allow remote authenticated users to create arbitrary files and execute code via the (1) vMME.AttachmentPath or (2) vMME.LibraryPath variables.
ModificadaAlta (7.5)1.5%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SQL injection vulnerability in SalesLogix 6.1 allows remote attackers to execute arbitrary SQL statements via the id parameter in a view operation.
ModificadaMedia (5)1.8%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
SalesLogix 6.1 includes usernames, passwords, and other sensitive information in the headers of an HTTP response, which could allow remote attackers to gain access.
ModificadaMedia (5)1.8%—Best Software SaleslogixSaleslogix Corporation Saleslogix18/10/200416/6/2026
slxweb.dll in SalesLogix 6.1 allows remote attackers to obtain sensitive information via a (1) Library or (2) Attachment request with an invalid file parameter, which reveals the path in an error message.