Goal Reached Thanks to every supporter — we hit 100%!

Goal: 1000 CNY · Raised: 1000 CNY

100.0%

Rockwell Automation — Vulnerabilities & Security Advisories 259

Browse all 259 CVE security advisories affecting Rockwell Automation. AI-powered Chinese analysis, POCs, and references for each vulnerability.

Rockwell Automation specializes in industrial automation and information integration, providing critical control systems for manufacturing and process industries. Its software portfolio, including FactoryTalk and PlantPAx, manages complex operational technology environments, making it a high-value target for threat actors seeking to disrupt industrial infrastructure. Historical vulnerability data reveals a prevalence of remote code execution, cross-site scripting, and privilege escalation flaws, often stemming from legacy components or insufficient input validation in web-based interfaces. Notable incidents include the 2018 discovery of backdoors in FactoryTalk View SE, which allowed unauthorized access to industrial control systems. These vulnerabilities highlight the persistent risk of insecure default configurations and unpatched legacy systems within industrial networks. The sheer volume of recorded CVEs underscores the complexity of securing interconnected OT/IT environments, where updates must balance operational continuity with rigorous security hygiene to prevent catastrophic physical or data breaches.

CVE IDTitleCVSSSeverityPublished
CVE-2021-32960 Rockwell Automation FactoryTalk Services Platform Protection Mechanism Failure — FactoryTalk Services Platform 8.5 High2022-04-01
CVE-2021-27475 Rockwell Automation Connected Components Workbench Deserialization of Untrusted Data — Connected Components WorkbenchCWE-502 8.6 High2022-03-23
CVE-2021-27471 Rockwell Automation Connected Components Workbench Path Traversal — Connected Components WorkbenchCWE-22 7.7 High2022-03-23
CVE-2021-27473 Rockwell Automation Connected Components Workbench Improper Input Validation — Connected Components WorkbenchCWE-22 6.1 Medium2022-03-23
CVE-2021-27476 Rockwell Automation FactoryTalk AssetCentre OS Command Injection — FactoryTalk AssetCentreCWE-78 10.0 Critical2022-03-23
CVE-2021-27470 Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data — FactoryTalk AssetCentreCWE-502 10.0 Critical2022-03-23
CVE-2021-27466 Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data — FactoryTalk AssetCentreCWE-502 10.0 Critical2022-03-23
CVE-2021-27474 Rockwell Automation FactoryTalk AssetCentre Use of Potentially Dangerous Function — FactoryTalk AssetCentreCWE-676 10.0 Critical2022-03-23
CVE-2021-27468 Rockwell Automation FactoryTalk AssetCentre SQL Injection — FactoryTalk AssetCentreCWE-89 10.0 Critical2022-03-23
CVE-2021-27472 Rockwell Automation FactoryTalk AssetCentre SQL Injection — FactoryTalk AssetCentreCWE-89 10.0 Critical2022-03-23
CVE-2021-27462 Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data — FactoryTalk AssetCentreCWE-502 10.0 Critical2022-03-23
CVE-2021-27464 Rockwell Automation FactoryTalk AssetCentre SQL Injection — FactoryTalk AssetCentreCWE-89 10.0 Critical2022-03-23
CVE-2021-27460 Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data — FactoryTalk AssetCentreCWE-502 10.0 Critical2022-03-23
CVE-2020-25180 Rockwell Automation ISaGRAF5 Runtime Use of Hard-coded Cryptographic Key — ISaGRAF RuntimeCWE-321 5.3 Medium2022-03-18
CVE-2020-25184 Rockwell Automation ISaGRAF5 Runtime Unprotected Storage of Credentials — ISaGRAF RuntimeCWE-256 7.8 High2022-03-18
CVE-2020-25176 Rockwell Automation ISaGRAF5 Runtime Relative Path Traversal — ISaGRAF RuntimeCWE-23 9.1 Critical2022-03-18
CVE-2020-25178 Rockwell Automation ISaGRAF5 Runtime Cleartext Transmission of Sensitive Information — ISaGRAF RuntimeCWE-319 7.5 High2022-03-18
CVE-2020-25182 Rockwell Automation ISaGRAF5 Runtime Uncontrolled Search Path Element — ISaGRAF RuntimeCWE-427 6.7 Medium2022-03-18
CVE-2020-14480 Rockwell Automation FactoryTalk View SE 安全漏洞 — FactoryTalk View SECWE-312 7.1 -2022-02-24
CVE-2020-14481 Rockwell Automation FactoryTalk View SE 加密问题漏洞 — FactoryTalk View SECWE-261 7.8 -2022-02-24
CVE-2020-14478 IMPROPER RESTRICTION OF XML EXTERNAL ENTITY REFERENCE CWE-611 — FactoryTalk Services PlatformCWE-611 7.1 -2022-02-24
CVE-2020-14502 Rockwell Automation 1734-AENTR 跨站脚本漏洞 — 1734-AENTRCWE-79 6.1 -2022-02-24
CVE-2020-14504 Rockwell Automation 1734-AENTR 授权问题漏洞 — 1734-AENTRCWE-284 7.5 -2022-02-24
CVE-2020-12028 Rockwell Automation FactoryTalk View SE — FactoryTalk View SECWE-264 7.3 High2020-07-20
CVE-2020-12027 Rockwell Automation FactoryTalk View SE — FactoryTalk View SECWE-200 4.3 Medium2020-07-20
CVE-2020-12031 Rockwell Automation FactoryTalk View SE — FactoryTalk View SECWE-119 7.5 High2020-07-20
CVE-2020-12029 Rockwell Automation FactoryTalk View SE — FactoryTalk View SECWE-20 9.0 Critical2020-07-20
CVE-2019-10952 Rockwell Automation CompactLogix 5370 Uncontrolled Resource Consumption — CompactLogix 5370 L1 controllersCWE-400 9.8 -2019-05-01
CVE-2019-10954 Rockwell Automation CompactLogix 5370 Stack-based Buffer Overflow — CompactLogix 5370 L1 controllersCWE-121 7.5 -2019-05-01
CVE-2019-10955 多款Rockwell Automation产品输入验证错误漏洞 — MicroLogix 1400 ControllersCWE-601 6.1 -2019-04-25

This page lists every published CVE security advisory associated with Rockwell Automation. Each entry links to a detailed page with CVSS scoring, CWE classification, affected products and references. AI-generated Chinese analysis is provided for fast triage.