Vulnerabilidades

Resumen — últimos 7 días

Vulnerabilidades nuevas3027▼ 35 respecto a la semana anterior
Críticas / altas1418▲ 79 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)390▼ 120 respecto a la semana anterior
–

11 resultados, ordenados por fecha de publicación (más recientes primero)

CVEEstadoSeveridadEPSS Explotación activaTecnologías afectadasPublicada ▼Modificada Descripción
AnalizadaAlta (8.7)0.55%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Controllogix 5580 Process FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 Firmware+414/10/202417/6/2026
CVE 2021-22681 https://www.rockwellautomation.com/en-us/trust-center/security-advisories/advisory.PN1550.html and send a specially crafted CIP message to the device. If exploited, a threat actor could help prevent access to the legitimate user and end connections to connected devices including the workstation. To…
AnalizadaAlta (8.7)0.52%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+28/10/202417/6/2026
Due to a memory leak, a denial-of-service vulnerability exists in the Rockwell Automation affected products. A malicious actor could exploit this vulnerability by performing multiple actions on certain web pages of the product causing the affected products to become fully unavailable and require a power cycle to…
AnalizadaAlta (8.7)0.56%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 3 FirmwareRockwellautomation Compactlogix 5480 Firmware+312/9/202417/6/2026
A denial-of-service vulnerability exists in the Rockwell Automation affected products when specially crafted packets are sent to the CIP Security Object. If exploited the device will become unavailable and require a factory reset to recover.
AnalizadaAlta (8.7)0.52%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+214/8/202417/6/2026
CVE-2024-7515 IMPACT A denial-of-service vulnerability exists in the affected products. A malformed PTP management packet can cause a major nonrecoverable fault in the controller.
AnalizadaAlta (8.7)0.50%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 SIL 2 Firmware+214/8/202417/6/2026
CVE-2024-7507 IMPACT A denial-of-service vulnerability exists in the affected products. This vulnerability occurs when a malformed PCCC message is received, causing a fault in the controller.
AnalizadaAlta (8.3)0.31%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation 1756-en4 FirmwareRockwellautomation Compactlogix 5380 Firmware+214/6/202417/6/2026
Rockwell Automation was made aware of a vulnerability that causes all affected controllers on the same network to result in a major nonrecoverable fault(MNRF/Assert). This vulnerability could be exploited by sending abnormal packets to the mDNS port. If exploited, the availability of the device would be compromised.
AnalizadaAlta (7.5)0.64%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+415/4/202417/6/2026
A specific malformed fragmented packet type (fragmented packets may be generated automatically by devices that send large amounts of data) can cause a major nonrecoverable fault (MNRF) Rockwell Automation's ControlLogix 5580, Guard Logix 5580, CompactLogix 5380, and 1756-EN4TR. If exploited, the affected product will…
ModificadaAlta (7.5)1.3%—Rockwellautomation Compactlogix 5480 FirmwareRockwellautomation Compactlogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compact Guardlogix 5380 Firmware+119/12/202217/6/2026
An unauthorized user could use a specially crafted sequence of Ethernet/IP messages, combined with heavy traffic loading to cause a denial-of-service condition in Rockwell Automation Logix controllers resulting in a major non-recoverable fault. If the target device becomes unavailable, a user would have to clear the…
ModificadaAlta (8.6)2.1%—Rockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compact Guardlogix 5380 FirmwareRockwellautomation Compactlogix 5480 FirmwareRockwellautomation Controllogix 5580 Firmware+52/6/202217/6/2026
A malformed Class 3 common industrial protocol message with a cached connection can cause a denial-of-service condition in Rockwell Automation Logix Controllers, resulting in a major nonrecoverable fault. If the target device becomes unavailable, a user would have to clear the fault and redownload the user project…
ModificadaCrítica (9.8)5.2%—Rockwellautomation Compactlogix 1768-l43 FirmwareRockwellautomation Compactlogix 1768-l45 FirmwareRockwellautomation Compactlogix 1769-l31 FirmwareRockwellautomation Compactlogix 1769-l32c Firmware+2011/4/202217/6/2026
An attacker with the ability to modify a user program may change user program code on some ControlLogix, CompactLogix, and GuardLogix Control systems. Studio 5000 Logix Designer writes user-readable program code to a separate location than the executed compiled code, allowing an attacker to change one and not the…
ModificadaAlta (7.2)3.5%—Rockwellautomation Controllogix 5580 FirmwareRockwellautomation Guardlogix 5580 FirmwareRockwellautomation Compactlogix 5380 FirmwareRockwellautomation Compactlogix 5480 Firmware+11/4/202217/6/2026
Rockwell Automation Studio 5000 Logix Designer (all versions) are vulnerable when an attacker who achieves administrator access on a workstation running Studio 5000 Logix Designer could inject controller code undetectable to a user.