Rockwellautomation
Rockwellautomation Factorytalk Linx: vulnerabilidades y CVE
Rockwellautomation Factorytalk Linx tiene 14 vulnerabilidades publicadas, 2 de ellas en los últimos 12 meses. 3 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses2
Críticas3
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2025-9068 | Alta (8.5) | 0.18% | — | 14 oct 2025 | A security issue exists within the Rockwell Automation Driver Package x64 Microsoft Installer File (MSI) repair functionality, installed with FTLinx. Authenticated attackers with valid Windows Users credentials can… |
| CVE-2025-9067 | Alta (8.5) | 0.18% | — | 14 oct 2025 | A security issue exists within the x86 Microsoft Installer File (MSI), installed with FTLinx. Authenticated attackers with valid Windows user credentials can initiate a repair and hijack the resulting console window.… |
| CVE-2025-7972 | Alta (8.4) | 0.50% | — | 14 ago 2025 | A security issue exists within the FactoryTalk Linx Network Browser. By modifying the process.env.NODE_ENV to ‘development’, the attacker can disable FTSP token validation. This bypass allows access to create, update,… |
| CVE-2023-29464 | Crítica (9.1) | 9.6% | — | 13 oct 2023 | FactoryTalk Linx, in the Rockwell Automation PanelView Plus, allows an unauthenticated threat actor to read data from memory via crafted malicious packets. Sending a size larger than the buffer size results in leakage… |
| CVE-2020-5806 | Media (5.5) | 4.8% | — | 29 dic 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in the CServerManager::HandleBrowseLoadIconStreamRequest in messaging.dll. This can be done by sending a specially crafted message to… |
| CVE-2020-5802 | Alta (7.5) | 39% | — | 29 dic 2020 | An attacker-controlled memory allocation size can be passed to the C++ new operator in RnaDaSvr.dll by sending a specially crafted ConfigureItems message to TCP port 4241. This will cause an unhandled exception,… |
| CVE-2020-5801 | Alta (7.5) | 25% | — | 29 dic 2020 | An attacker can craft and send an OpenNamespace message to port 4241 with valid session-id that triggers an unhandled exception in CFTLDManager::HandleRequest function in RnaDaSvr.dll, resulting in process termination.… |
| CVE-2020-27255 | Alta (7.5) | 3.9% | — | 26 nov 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious set attribute requests, which could result in the… |
| CVE-2020-27253 | Alta (7.5) | 1.9% | — | 26 nov 2020 | A flaw exists in the Ingress/Egress checks routine of FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to specifically craft a malicious packet resulting in a… |
| CVE-2020-27251 | Crítica (9.8) | 6.8% | — | 26 nov 2020 | A heap overflow vulnerability exists within FactoryTalk Linx Version 6.11 and prior. This vulnerability could allow a remote, unauthenticated attacker to send malicious port ranges, which could result in remote code… |
| CVE-2020-12005 | Alta (7.5) | 1.8% | — | 15 jun 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later,… |
| CVE-2020-12003 | Alta (7.5) | 5.2% | — | 15 jun 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later,… |
| CVE-2020-12001 | Crítica (9.8) | 12% | — | 15 jun 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later,… |
| CVE-2020-11999 | Alta (8.1) | 2.8% | — | 15 jun 2020 | FactoryTalk Linx versions 6.00, 6.10, and 6.11, RSLinx Classic v4.11.00 and prior,Connected Components Workbench: Version 12 and prior, ControlFLASH: Version 14 and later, ControlFLASH Plus: Version 1 and later,… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Rockwellautomation
Arena · 46Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Micrologix 1100 Firmware · 14Factorytalk Services Platform · 14Controllogix 5580 Firmware · 13Guardlogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11Micrologix 1400 Firmware · 11