« Back to list

Rockwellautomation

Rockwellautomation Studio 5000 Simulation Interface: vulnerabilities and CVEs

Rockwellautomation Studio 5000 Simulation Interface has 2 published vulnerabilities, 2 of them in the last 12 months. 0 are rated critical and 0 are listed by CISA as actively exploited.

CVEs2
Last 12 months2
Critical0
Actively exploited0

All vulnerabilities in the catalogue →⭐ Follow this technology

Latest vulnerabilities

CVESeverityEPSSActive exploitationPublishedDescription
CVE-2025-11697High (8.9)0.14%—Nov 11, 2025
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in…
CVE-2025-11696High (8.9)0.17%—Nov 11, 2025
A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling…

🎯 How it gets exploited (ATT&CK techniques)

  1. T1068 Exploitation for Privilege Escalation2
  2. T1005 Data from Local System1
  3. T1552.007 Container API1

Number of CVEs of this technology mapped to each exploitation or primary-impact technique.

Other products by Rockwellautomation