Rockwellautomation
Rockwellautomation Factorytalk Services Platform: vulnerabilidades y CVE
Rockwellautomation Factorytalk Services Platform tiene 14 vulnerabilidades publicadas, 1 de ellas en los últimos 12 meses. 4 son críticas y 1 figuran en el catálogo de explotación activa de CISA.
CVE14
Últimos 12 meses1
Críticas4
Explotadas activamente1
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
🔴 Explotadas activamente (CISA KEV)
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-22681 | Crítica (9.8) | 64% | ⚠ Explotación activa | 3 mar 2021 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769,… |
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2026-10714 | Alta (8.8) | 0.15% | — | 14 jul 2026 | A security issue exists within FactoryTalk® Services Platform (FTSP), allowing an attacker to bypass JWT signature validation during Okta Web Authentication. The vulnerability stems from the application not verifying… |
| CVE-2024-21915 | Alta (8.8) | 0.99% | — | 16 feb 2024 | A privilege escalation vulnerability exists in Rockwell Automation FactoryTalk® Service Platform (FTSP). If exploited, a malicious user with basic user group privileges could potentially sign into the software and… |
| CVE-2024-21917 | Crítica (9.1) | 0.86% | — | 31 ene 2024 | A vulnerability exists in Rockwell Automation FactoryTalk® Service Platform that allows a malicious user to obtain the service token and use it for authentication on another FTSP directory. This is due to the lack of… |
| CVE-2023-46290 | Alta (8.1) | 2.7% | — | 27 oct 2023 | Due to inadequate code logic, a previously unauthenticated threat actor could potentially obtain a local Windows OS user token through the FactoryTalk® Services Platform web service and then use the token to log in into… |
| CVE-2021-32960 | Alta (8.8) | 2.4% | — | 1 abr 2022 | Rockwell Automation FactoryTalk Services Platform v6.11 and earlier, if FactoryTalk Security is enabled and deployed contains a vulnerability that may allow a remote, authenticated attacker to bypass FactoryTalk… |
| CVE-2020-14478 | Alta (7.1) | 0.34% | — | 24 feb 2022 | A local, authenticated attacker could use an XML External Entity (XXE) attack to exploit weakly configured XML files to access local or remote content. A successful exploit could potentially cause a denial-of-service… |
| CVE-2020-14516 | Crítica (10) | 4.1% | — | 18 mar 2021 | In Rockwell Automation FactoryTalk Services Platform Versions 6.10.00 and 6.11.00, there is an issue with the implementation of the SHA-256 hashing algorithm with FactoryTalk Services Platform that prevents the user… |
| CVE-2021-22681 | Crítica (9.8) | 64% | ⚠ Explotación activa | 3 mar 2021 | Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell Automation CompactLogix 1768, 1769,… |
| CVE-2020-12033 | Alta (8.8) | 1.1% | — | 23 jun 2020 | In Rockwell Automation FactoryTalk Services Platform, all versions, the redundancy host service (RdcyHost.exe) does not validate supplied identifiers, which could allow an unauthenticated, adjacent attacker to execute… |
| CVE-2020-6967 | Crítica (9.8) | 5.5% | — | 23 mar 2020 | In Rockwell Automation all versions of FactoryTalk Diagnostics software, a subsystem of the FactoryTalk Services Platform, FactoryTalk Diagnostics exposes a .NET Remoting endpoint via RNADiagnosticsSrv.exe at… |
| CVE-2018-18981 | Alta (7.5) | 3.9% | — | 24 ene 2019 | In Rockwell Automation FactoryTalk Services Platform 2.90 and earlier, a remote unauthenticated attacker could send numerous crafted packets to service ports resulting in memory consumption that could lead to a partial… |
| CVE-2014-9209 | Media (6.9) | 0.69% | — | 31 mar 2015 | Untrusted search path vulnerability in the Clean Utility application in Rockwell Automation FactoryTalk Services Platform before 2.71.00 and FactoryTalk View Studio 8.00.00 and earlier allows local users to gain… |
| CVE-2012-4714 | Alta (7.8) | 3.2% | — | 18 abr 2013 | Integer overflow in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to cause a… |
| CVE-2012-4713 | Alta (7.8) | 3.2% | — | 18 abr 2013 | Integer signedness error in RNADiagnostics.dll in Rockwell Automation FactoryTalk Services Platform (FTSP) CPR9, CPR9-SR1, CPR9-SR2, CPR9-SR3, CPR9-SR4, CPR9-SR5, CPR9-SR5.1, and CPR9-SR6 allows remote attackers to… |
🎯 Cómo se explota (técnicas ATT&CK)
Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.
Otros productos de Rockwellautomation
Arena · 46Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Micrologix 1100 Firmware · 14Factorytalk Linx · 14Controllogix 5580 Firmware · 13Guardlogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11Micrologix 1400 Firmware · 11