Rockwellautomation
Rockwellautomation Controllogix: vulnerabilidades y CVE
Rockwellautomation Controllogix tiene 9 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE9
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2024-6098 | Media (5.9) | 0.40% | — | 16 ago 2024 | When performing an online tag generation to devices which communicate using the ControlLogix protocol, a machine-in-the-middle, or a device that is not configured correctly, could deliver a response leading to… |
| CVE-2024-6242 | Alta (7.3) | 11% | — | 1 ago 2024 | A vulnerability exists in Rockwell Automation affected products that allows a threat actor to bypass the Trusted® Slot feature in a ControlLogix® controller. If exploited on any affected module in a 1756 chassis, a… |
| CVE-2012-6441 | Media (5) | 57% | — | 24 ene 2013 | An information exposure of confidential information results when the device receives a specially crafted CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP. Successful exploitation of this… |
| CVE-2012-6440 | Media (4.8) | 9.3% | — | 24 ene 2013 | The Web server password authentication mechanism used by the products is vulnerable to a MitM and Replay attack. Successful exploitation of this vulnerability will allow unauthorized access of the product’s Web server… |
| CVE-2012-6439 | Alta (8.5) | 23% | — | 24 ene 2013 | When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that changes the product’s configuration and network… |
| CVE-2012-6438 | Alta (7.5) | 27% | — | 24 ene 2013 | The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow… |
| CVE-2012-6437 | Crítica (9.8) | 7.8% | — | 24 ene 2013 | The device does not properly authenticate users and the potential exists for a remote user to upload a new firmware image to the Ethernet card, whether it is a corrupt or legitimate firmware image. Successful… |
| CVE-2012-6436 | Alta (7.5) | 27% | — | 24 ene 2013 | The device does not properly validate the data being sent to the buffer. An attacker can send a malformed CIP packet to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP, which creates a buffer overflow… |
| CVE-2012-6435 | Alta (7.5) | 33% | — | 24 ene 2013 | When an affected product receives a valid CIP message from an unauthorized or unintended source to Port 2222/TCP, Port 2222/UDP, Port 44818/TCP, or Port 44818/UDP that instructs the CPU to stop logic execution and enter… |
Otros productos de Rockwellautomation
Arena · 46Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Factorytalk Linx · 14Micrologix 1100 Firmware · 14Factorytalk Services Platform · 14Controllogix 5580 Firmware · 13Guardlogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11