Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas2987▼ 96 respecto a la semana anterior
Críticas / altas1458▲ 101 respecto a la semana anterior
Nueva explotación activa (KEV)4▼ 5 respecto a la semana anterior
Sin puntuar (sin CVSS)350▼ 160 respecto a la semana anterior
23 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Modificada | Media (6.1) | 0.56% | — | Rockwellautomation Micrologix 1400 FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Micrologix 1400-b FirmwareRockwellautomation Micrologix 1400-c Firmware+1 | 16/12/2022 | 17/6/2026 | Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the ability to accomplish remote code execution. The vulnerability is an unauthenticated stored cross-site… | |
| Modificada | Crítica (9.8) | 4.4% | — | Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 500 | 16/3/2020 | 17/6/2026 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic key utilized to help protect the account password is hard coded into the RSLogix 500 binary file. An attacker could… | |
| Modificada | Alta (7.5) | 4.0% | — | Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 500 | 16/3/2020 | 17/6/2026 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, A remote, unauthenticated attacker can send a request from the RSLogix 500 software to the victim’s MicroLogix controller. The controller… | |
| Modificada | Alta (7.5) | 2.8% | — | Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 500 | 16/3/2020 | 17/6/2026 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, The cryptographic function utilized to protect the password in MicroLogix is discoverable. | |
| Modificada | Baja (3.3) | 0.41% | — | Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Rslogix 500 | 16/3/2020 | 17/6/2026 | Rockwell Automation MicroLogix 1400 Controllers Series B v21.001 and prior, Series A, all versions, MicroLogix 1100 Controller, all versions, RSLogix 500 Software v12.001 and prior, If Simple Mail Transfer Protocol (SMTP) account data is saved in RSLogix 500, a local attacker with access to a victim’s project may be… | |
| Modificada | Media (6.1) | 3.1% | — | Rockwellautomation Micrologix 1400 A FirmwareRockwellautomation Micrologix 1400 B FirmwareRockwellautomation Micrologix 1100 FirmwareRockwellautomation Compactlogix 5370 L1 Firmware+2 | 25/4/2019 | 17/6/2026 | In Rockwell Automation MicroLogix 1400 Controllers Series A, All Versions Series B, v15.002 and earlier, MicroLogix 1100 Controllers v14.00 and earlier, CompactLogix 5370 L1 controllers v30.014 and earlier, CompactLogix 5370 L2 controllers v30.014 and earlier, CompactLogix 5370 L3 controllers (includes CompactLogix… | |
| Modificada | Alta (7.5) | 2.7% | — | Rockwellautomation Micrologix 1400 B Firmware | 4/6/2018 | 17/6/2026 | An exploitable file write vulnerability exists in the memory module functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a file write resulting in a new program being written to the memory module. An attacker can send an unauthenticated packet to trigger… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 37% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 35% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 38% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 39% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Crítica (9.8) | 35% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable access control vulnerability exists in the data, program, and function file permissions functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a read or write operation resulting in disclosure of sensitive information, modification of settings,… | |
| Modificada | Media (5.3) | 6.0% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable insufficient resource pool vulnerability exists in the session communication functionality of Allen Bradley Micrologix 1400 Series B Firmware 21.2 and before. A specially crafted stream of packets can cause a flood of the session resource pool resulting in legitimate connections to the PLC being… | |
| Modificada | Alta (7.5) | 4.7% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the processing of snmp-set commands of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted snmp-set request, when sent without associated firmware flashing snmp-set commands, can cause a device power cycle resulting in downtime for… | |
| Modificada | Alta (7.5) | 4.8% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the program download functionality of Allen Bradley Micrologix 1400 Series B FRN 21.2 and before. A specially crafted packet can cause a device fault resulting in halted operations. An attacker can send an unauthenticated packet to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 4.6% | — | Rockwellautomation Micrologix 1400 B Firmware | 5/4/2018 | 17/6/2026 | An exploitable denial of service vulnerability exists in the Ethernet functionality of the Allen Bradley Micrologix 1400 Series B FRN 21.2 and below. A specially crafted packet can cause a device power cycle resulting in a fault state and deletion of ladder logic. An attacker can send one unauthenticated packet to… |