Vulnerabilidades
Resumen — últimos 7 días
Vulnerabilidades nuevas3001▼ 62 respecto a la semana anterior
Críticas / altas1373▲ 34 respecto a la semana anterior
Nueva explotación activa (KEV)5▼ 3 respecto a la semana anterior
Sin puntuar (sin CVSS)459▼ 50 respecto a la semana anterior
24 resultados, ordenados por fecha de publicación (más recientes primero)
| CVE | Estado | Severidad | EPSS | Explotación activa | Tecnologías afectadas | Publicada ▼ | Modificada | Descripción |
|---|---|---|---|---|---|---|---|---|
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet with an oversized embedded message request can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet can cause the RSLinx® Classic service to crash due to insufficient data length validation, requiring a restart of the service to recover. | |
| Pendiente de análisis | Alta (8.7) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. A crafted CIP packet targeting the Forward Close service can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover. | |
| Pendiente de análisis | Crítica (9.2) | 0.43% | — | Rockwellautomation Rslinx ClassicAI | 1/9/2026 | 1/9/2026 | A denial-of-service security issue exists within RSLinx® Classic. The security issue stems from improper handling of a malformed packet. A crafted CIP packet can cause the RSLinx® Classic service to crash, requiring a restart of the service to recover | |
| Modificada | Alta (7.5) | 3.5% | — | Rockwellautomation Rslinx | 7/1/2021 | 17/6/2026 | A denial-of-service vulnerability exists in the Ethernet/IP server functionality of Rockwell Automation RSLinx Classic 2.57.00.14 CPR 9 SR 3. A specially crafted network request can lead to a denial of service. An attacker can send a sequence of malicious packets to trigger this vulnerability. | |
| Modificada | Alta (7.5) | 1.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (7.5) | 5.2% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Crítica (9.8) | 12% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (8.1) | 2.8% | — | Rockwellautomation Factorytalk LinxRockwellautomation Rslinx Classic | 15/6/2020 | 17/6/2026 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later, FactoryTalk Asset Centre: Version 9 and later, FactoryTalk Linx CommDTM: Version 1 and later, Studio 5000… | |
| Modificada | Alta (8.2) | 1.3% | — | Rockwellautomation EDS SubsystemRockwellautomation RslinxRockwellautomation Rslinx EnterpriseRockwellautomation Rsnetworx+1 | 20/5/2020 | 17/6/2026 | Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is… | |
| Modificada | Media (5.5) | 2.6% | — | Rockwellautomation EDS SubsystemRockwellautomation RslinxRockwellautomation Rslinx EnterpriseRockwellautomation Rsnetworx+1 | 19/5/2020 | 17/6/2026 | Products that use EDS Subsystem: Version 28.0.1 and prior (FactoryTalk Linx software (Previously called RSLinx Enterprise): Versions 6.00, 6.10, and 6.11, RSLinx Classic: Version 4.11.00 and prior, RSNetWorx software: Version 28.00.00 and prior, Studio 5000 Logix Designer software: Version 32 and prior) is vulnerable.… | |
| Modificada | Alta (7.8) | 0.45% | — | Rockwellautomation Rslinx Classic | 13/4/2020 | 17/6/2026 | In Rockwell Automation RSLinx Classic versions 4.11.00 and prior, an authenticated local attacker could modify a registry key, which could lead to the execution of malicious code using system privileges when opening RSLinx Classic. | |
| Modificada | Crítica (9.8) | 66% | — | Rockwellautomation Rslinx | 4/4/2019 | 17/6/2026 | A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward Open service request is passed to a fixed size buffer, allowing an attacker to exploit a stack-based buffer overflow condition. | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Rslinx Enterprise | 26/3/2019 | 16/6/2026 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it receives a datagram with an incorrect value in the “Record Data Size” field. By sending a datagram to the… | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Rslinx Enterprise | 26/3/2019 | 16/6/2026 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “Total Record Size” field. By sending a datagram to the service over… | |
| Modificada | Alta (7.5) | 3.9% | — | Rockwellautomation Rslinx Enterprise | 26/3/2019 | 16/6/2026 | Rockwell Automation RSLinx Enterprise Software (LogReceiver.exe) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 does not handle input correctly and results in a logic error if it calculates an incorrect value for the “End of Current Record” field. By sending a datagram to the service… | |
| Modificada | Crítica (9.8) | 16% | — | Rockwellautomation Rslinx | 20/9/2018 | 17/6/2026 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote threat actor to intentionally send a malformed CIP packet to Port 44818, causing the software application to stop responding and crash. This vulnerability also has the potential to exploit a buffer overflow condition,… | |
| Modificada | Alta (7.5) | 3.8% | — | Rockwellautomation Rslinx | 20/9/2018 | 17/6/2026 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. A remote, unauthenticated threat actor may intentionally send specially crafted Ethernet/IP packets to Port 44818, causing the software application to stop responding and crash. The user must restart the software to regain functionality. | |
| Modificada | Alta (7.5) | 4.5% | — | Rockwellautomation Rslinx | 20/9/2018 | 17/6/2026 | Rockwell Automation RSLinx Classic Versions 4.00.01 and prior. This vulnerability may allow a remote, unauthenticated threat actor to intentionally send a malformed CIP packet to Port 44818, causing the RSLinx Classic application to terminate. The user will need to manually restart the software to regain functionality. | |
| Modificada | Alta (7.8) | 2.8% | — | Rockwellautomation Rslinx ClassicRockwellautomation Factorytalk Linx Gateway | 7/6/2018 | 17/6/2026 | An unquoted search path or element in RSLinx Classic Versions 3.90.01 and prior and FactoryTalk Linx Gateway Versions 3.90.00 and prior may allow an authorized, but non-privileged local user to execute arbitrary code and allow a threat actor to escalate user privileges on the affected workstation. | |
| Modificada | Media (6.9) | 1.6% | — | Rockwellautomation Rslinx | 17/5/2015 | 17/6/2026 | Stack-based buffer overflow in OPCTest.exe in Rockwell Automation RSLinx Classic before 3.73.00 allows remote attackers to execute arbitrary code via a crafted CSV file. | |
| Modificada | Alta (10) | 7.8% | — | Rockwellautomation Rslinx Enterprise | 18/4/2013 | 16/6/2026 | Buffer overflow in LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (daemon crash) or possibly execute arbitrary code via a UDP packet with a certain integer length value that… | |
| Modificada | Alta (7.1) | 2.8% | — | Rockwellautomation Rslinx Enterprise | 18/4/2013 | 16/6/2026 | LogReceiver.exe in Rockwell Automation RSLinx Enterprise CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a denial of service (service outage) via a zero-byte UDP packet that is not properly handled by Logger.dll. | |
| Modificada | Alta (9.3) | 7.6% | — | Rockwellautomation RslinxRockwellautomation EDS Hardware Installation Tool | 22/6/2011 | 16/6/2026 | Buffer overflow in RSEds.dll in RSHWare.exe in the EDS Hardware Installation Tool 1.0.5.1 and earlier in Rockwell Automation RSLinx Classic before 2.58 allows user-assisted remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via a malformed .eds file. |