Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Rockwell Automation — Vulnerabilities & Security Advisories 259

Browse all 259 CVE security advisories affecting Rockwell Automation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rockwell Automation specializes in industrial automation and information integration, providing critical control systems for manufacturing and process industries. Its software portfolio, including FactoryTalk and PlantPAx, manages complex operational technology environments, making it a high-value target for threat actors seeking to disrupt industrial infrastructure. Historical vulnerability data reveals a prevalence of remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from legacy components or insufficient input validation in web-based interfaces. Notable incidents include the 2018 discovery of backdoors in FactoryTalk View SE, which allowed unauthorized access to industrial control systems. These vulnerabilities highlight the persistent risk of insecure default configurations and unpatched legacy systems within industrial networks. The sheer volume of recorded CVEs underscores the complexity of securing interconnected OT/IT environments, where updates must balance operational continuity with rigorous security hygiene to prevent catastrophic physical or data breaches.

CVE IDTitleCVSSSeverityPublished
CVE-2025-3617 Local Privilege Escalation in ThinManager® — ThinManager® 7.8AIHighAI2025-04-15
CVE-2025-3289 Local Code Execution Vulnerability in Arena® — Arena® 8.6AIHighAI2025-04-08
CVE-2025-3288 Local Code Execution Vulnerability in Arena® — Arena®CWE-125 7.8AIHighAI2025-04-08
CVE-2025-3287 Local Code Execution Vulnerability in Arena® — Arena®CWE-125 8.6AIHighAI2025-04-08
CVE-2025-3286 Local Code Execution Vulnerability in Arena® — Arena®CWE-125 7.8AIHighAI2025-04-08
CVE-2025-3285 Local Code Execution Vulnerability in Arena® — Arena®CWE-125 7.8AIHighAI2025-04-08
CVE-2025-2829 Local Code Execution Vulnerability in Arena® — Arena®CWE-787 7.8AIHighAI2025-04-08
CVE-2025-2293 Local Code Execution Vulnerability in Arena® — Arena®CWE-787 7.8AIHighAI2025-04-08
CVE-2025-2288 Local Code Execution Vulnerability in Arena® — Arena®CWE-787 7.8AIHighAI2025-04-08
CVE-2025-2287 Local Code Execution Vulnerability in Arena® — Arena®CWE-457 8.6AIHighAI2025-04-08
CVE-2025-2286 Local Code Execution Vulnerability in Arena® — Arena®CWE-457 8.6AIHighAI2025-04-08
CVE-2025-2285 Local Code Execution Vulnerability in Arena® — Arena®CWE-457 8.6AIHighAI2025-04-08
CVE-2025-1449 Admin Shell Access Vulnerability in Rockwell Automation Verve Asset Manager — Verve Asset Manager 7.2 -2025-03-31
CVE-2025-0477 Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability — FactoryTalk® AssetCentreCWE-522 7.5 -2025-01-30
CVE-2025-0497 Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability — FactoryTalk® AssetCentreCWE-522 6.5 -2025-01-30
CVE-2025-0498 Rockwell Automation FactoryTalk® AssetCentre Data Exposure Vulnerability — FactoryTalk® AssetCentreCWE-522 8.2 -2025-01-30
CVE-2025-24482 FactoryTalk® View Site Edition - Local Code Injection — FactoryTalk® View Site EditionCWE-94 7.8 -2025-01-28
CVE-2025-24481 FactoryTalk® View Site Edition - Incorrect Permission Assignment — FactoryTalk® View Site EditionCWE-732 9.8 -2025-01-28
CVE-2025-24480 FactoryTalk® View Machine Editon - Remote Code Execution — FactoryTalk® View Machine EditionCWE-78 9.8 -2025-01-28
CVE-2025-24479 FactoryTalk® View Machine Edition - Local Code Injection — FactoryTalk View Machine EditionCWE-863 7.8 -2025-01-28
CVE-2025-24478 5380/5580 Denial-of-Service Vulnerability — GuardLogix 5580 SIL 3CWE-755 7.5 -2025-01-28
CVE-2025-0631 PowerFlex® 755 Credential Exposure Vulnerability — PowerFlex 755CWE-319 7.5 -2025-01-28
CVE-2025-0659 Path Traversal and Rockwell Automation Third-party Vulnerability in DataMosaix™ Private Cloud — DataEdgePlatform DataMosaix™ Private CloudCWE-200 4.9 -2025-01-28
CVE-2024-11364 Rockwell Automation Third Party Vulnerability in Arena® — Arena® 7.8 -2024-12-19
CVE-2024-12672 Rockwell Automation Third Party Vulnerability in Arena® — Arena® 9.8 -2024-12-19
CVE-2024-12175 Rockwell Automation Code Execution Vulnerability in Arena — Arena® 7.8 -2024-12-19
CVE-2024-11157 Rockwell Automation Third Party Vulnerability in Arena — Arena® 9.8 -2024-12-19
CVE-2024-12373 Rockwell Automation PowerMonitor™ 1000 Denial of Service — PM1k 1408-BC3A-485 7.5 -2024-12-18
CVE-2024-12372 Rockwell Automation PowerMonitor™ 1000 Denial of Service — PM1k 1408-BC3A-485 9.8 -2024-12-18
CVE-2024-12371 Rockwell Automation PowerMonitor™ 1000 Remote Code Execution — PM1k 1408-BC3A-485 8.8 -2024-12-18

This page lists every published CVE security advisory associated with Rockwell Automation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.