Rockwellautomation
Rockwellautomation Micrologix 1400 Firmware: vulnerabilidades y CVE
Rockwellautomation Micrologix 1400 Firmware tiene 11 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 1 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE11
Últimos 12 meses0
Críticas1
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2022-46670 | Media (6.1) | 0.56% | — | 16 dic 2022 | Rockwell Automation was made aware of a vulnerability by a security researcher from Georgia Institute of Technology that the MicroLogix 1100 and 1400 controllers contain a vulnerability that may give an attacker the… |
| CVE-2022-3166 | Alta (7.5) | 0.70% | — | 16 dic 2022 | Rockwell Automation was made aware that the webservers of the Micrologix 1100 and 1400 controllers contain a vulnerability that may lead to a denial-of-service condition. The security vulnerability could be exploited by… |
| CVE-2022-2179 | Media (6.5) | 1.7% | — | 20 jul 2022 | The X-Frame-Options header in Rockwell Automation MicroLogix 1100/1400 Versions 21.007 and prior is not configured in the HTTP response, which could allow clickjacking attacks. |
| CVE-2021-32926 | Alta (7.5) | 3.0% | — | 3 jun 2021 | When an authenticated password change request takes place, this vulnerability could allow the attacker to intercept the message that includes the legitimate, new password hash and replace it with an illegitimate hash.… |
| CVE-2021-22659 | Alta (8.6) | 1.7% | — | 25 mar 2021 | Rockwell Automation MicroLogix 1400 Version 21.6 and below may allow a remote unauthenticated attacker to send a specially crafted Modbus packet allowing the attacker to retrieve or modify random values in the register.… |
| CVE-2018-17924 | Alta (8.6) | 4.3% | — | 7 dic 2018 | Rockwell Automation MicroLogix 1400 Controllers and 1756 ControlLogix Communications Modules An unauthenticated, remote threat actor could send a CIP connection request to an affected device, and upon successful… |
| CVE-2015-6492 | Alta (7.5) | 4.5% | — | 28 oct 2015 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote attackers to cause a denial of service (memory corruption and device crash) via a crafted HTTP request. |
| CVE-2015-6491 | Media (4) | 1.6% | — | 28 oct 2015 | Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allow remote authenticated users to insert the content of an arbitrary file into a FRAME element via unspecified vectors. |
| CVE-2015-6490 | Crítica (9.8) | 7.0% | — | 28 oct 2015 | Stack-based buffer overflow on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices through B FRN 15.003 allows remote attackers to execute arbitrary code via unspecified vectors. |
| CVE-2015-6488 | Media (4.3) | 2.8% | — | 28 oct 2015 | Cross-site scripting (XSS) vulnerability in the web server on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote attackers to inject arbitrary web script or HTML… |
| CVE-2015-6486 | Media (6.5) | 4.3% | — | 28 oct 2015 | SQL injection vulnerability on Allen-Bradley MicroLogix 1100 devices before B FRN 15.000 and 1400 devices before B FRN 15.003 allows remote authenticated users to execute arbitrary SQL commands via unspecified vectors. |
Otros productos de Rockwellautomation
Arena · 46Micrologix 1400 B Firmware · 22Factorytalk View · 18Thinmanager · 17Factorytalk Services Platform · 14Micrologix 1100 Firmware · 14Factorytalk Linx · 14Guardlogix 5580 Firmware · 13Controllogix 5580 Firmware · 13Factorytalk Assetcentre · 12Compactlogix 5380 Firmware · 12Compactlogix 5480 Firmware · 11