Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2768▼ 428 respecto a la semana anterior
Críticas / altas1324▼ 116 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)265▼ 243 respecto a la semana anterior
12 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (7) | 0.38% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user. | |
| Analizada | Alta (7.3) | 0.33% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages. | |
| Analizada | Crítica (9.3) | 0.37% | — | Rockwellautomation Factorytalk Assetcentre | 30/1/2025 | 17/6/2026 | An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application. | |
| Modificada | Crítica (9.8) | 4.1% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier. | |
| Modificada | Alta (7.5) | 1.6% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 5.7% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.9% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.5% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements. | |
| Modificada | Crítica (9.8) | 3.8% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre. | |
| Modificada | Crítica (9.8) | 3.2% | — | Rockwellautomation Factorytalk Assetcentre | 23/3/2022 | 17/6/2026 | Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk… |