Rockwellautomation
Rockwellautomation Connected Components Workbench: vulnerabilidades y CVE
Rockwellautomation Connected Components Workbench tiene 6 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE6
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-1018 | Media (5.5) | 2.2% | — | 1 abr 2022 | When opening a malicious solution file provided by an attacker, the application suffers from an XML external entity vulnerability due to an unsafe call within a dynamic link library file. An attacker could exploit this… |
| CVE-2021-27475 | Alta (8.6) | 3.0% | — | 23 mar 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a… |
| CVE-2021-27473 | Alta (8.2) | 0.78% | — | 23 mar 2022 | Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a… |
| CVE-2021-27471 | Alta (8.6) | 2.9% | — | 23 mar 2022 | The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected… |
| CVE-2017-5176 | Alta (7) | 0.52% | — | 19 may 2017 | A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier:… |
| CVE-2014-5424 | Alta (7.5) | 11% | — | 14 nov 2014 | Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an… |
Otros productos de Rockwellautomation
Arena · 46Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Factorytalk Services Platform · 14Micrologix 1100 Firmware · 14Factorytalk Linx · 14Guardlogix 5580 Firmware · 13Controllogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11