Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2663▼ 380 respecto a la semana anterior
Críticas / altas1289▼ 36 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)244▼ 274 respecto a la semana anterior
15 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can initiate a repair and hijack the resulting console window for vbpinstall.exe. This allows the launching… | |
| Analizada | Alta (8.5) | 0.18% | — | Rockwellautomation Factorytalk Linx | 14/10/2025 | 17/6/2026 | A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window. This allows the launching of a command prompt running with SYSTEM-level privileges, allowing full… | |
| Analizada | Alta (8.4) | 0.50% | — | Rockwellautomation Factorytalk Linx | 14/8/2025 | 17/6/2026 | A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update, and delete FTLinx drivers. | |
| Modificada | Crítica (9.1) | 9.6% | — | Rockwellautomation Factorytalk Linx | 13/10/2023 | 17/6/2026 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage of data from memory resulting in an information disclosure. If the size is large enough, it causes… | |
| Modificada | Media (5.5) | 4.8% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to 127.0.0.1:7153. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 39% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception, resulting in termination of RSLinxNG.exe. Observed in FactoryTalk 6.11. All versions of FactoryTalk Linx… | |
| Modificada | Alta (7.5) | 25% | — | Rockwellautomation Factorytalk Linx | 29/12/2020 | 17/6/2026 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination. Observed in FactoryTalk Linx 6.11. All versions of FactoryTalk Linx are affected. | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the leaking of sensitive information. This information disclosure could lead to the bypass of address… | |
| Modificada | Alta (7.5) | 1.9% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a denial-of-service condition on the device. | |
| Modificada | Crítica (9.8) | 6.8% | — | Rockwellautomation Factorytalk Linx | 26/11/2020 | 17/6/2026 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code execution. | |
| Modificada | Alta (7.5) | 1.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (7.5) | 5.2% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Crítica (9.8) | 12% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (8.1) | 2.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (7.8) | 2.8% | — | Rockwellautomation Rslinx ClassicRockwellautomation Factorytalk Linx Gateway | 7/6/2018 | 17/6/2026 | An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation. |