Rockwell Automation develops a broadly deployed portfolio of industrial control systems, programmable logic controllers, and manufacturing execution platforms that are critical to factory automation and process control across discrete and process industries. Vulnerabilities affecting the vendor skew toward serious outcomes, with an elevated share reaching critical severity, reflecting the memory-safety and input-validation demands of embedded and real-time control software. The exposure concentrates in flagship products such as Arena, MicroLogix 1400, FactoryTalk View, and ThinManager and recurs through weakness classes including improper input validation, out-of-bounds writes, memory-buffer management flaws, and uncontrolled resource consumption—patterns typical of industrial firmware and supervisory software that often prioritize availability and legacy protocol support over defense-in-depth. Defenders responsible for operational technology networks should prioritize inventory and segmentation of these systems, as remediation cycles in industrial environments are characteristically lengthy and many installations remain in service well beyond vendor support timelines. Current exploitation activity and severity distribution are shown alongside this summary.
The number and severity of CVEs published that impact products developed by Rockwellautomation over time
Signals from CVEs in this vendor scope (341 CVEs).
341 CVEs · Highest risk first
| CVE | Published | CVSS | Risk | KEV | Exploit |
|---|---|---|---|---|---|
CVE-2023-20198CRITICAL Cisco is providing an update for the ongoing investigation into observed exploitation of the web UI feature in Cisco IOS XE Software. We are updating the list of fixed releases and | Oct 16, 2023 | 10.0 | 99 | YES | YES |
CVE-2021-22681CRITICAL Rockwell Automation Studio 5000 Logix Designer Versions 21 and later, and RSLogix 5000 Versions 16 through 20 use a key to verify Logix controllers are communicating with Rockwell | Mar 3, 2021 | 9.8 | 90 | YES | NO |
CVE-2023-2917CRITICAL The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability. Due to an improper input validation, a path traversal vulnerability exist | Aug 17, 2023 | 9.8 | 79 | NO | YES |
CVE-2023-2915CRITICAL The Rockwell Automation Thinmanager Thinserver is impacted by an improper input validation vulnerability, Due to improper input validation, a path traversal vulnerability exists wh | Aug 17, 2023 | 9.1 | 75 | NO | YES |
CVE-2023-27856HIGH
In affected versions, path traversal exists when processing a message of type 8
in Rockwell Automation's ThinManager ThinServer.
An unauthenticated remote attacker can explo | Mar 22, 2023 | 7.5 | 71 | NO | YES |
CVE-2020-12028HIGH In all versions of FactoryTalk View SEA remote, an authenticated attacker may be able to utilize certain handlers to interact with the data on the remote endpoint since those handl | Jul 20, 2020 | 8.1 | 67 | NO | YES |
CVE-2010-2965CRITICAL The WDB target agent debug service in Wind River VxWorks 6.x, 5.x, and earlier, as used on the Rockwell Automation 1756-ENBT series A with firmware 3.2.6 and 3.6.1 and other produc | Aug 5, 2010 | 9.8 | 61 | NO | NO |
CVE-2019-6553CRITICAL A vulnerability was found in Rockwell Automation RSLinx Classic versions 4.10.00 and prior. An input validation issue in a .dll file of RSLinx Classic where the data in a Forward O | Apr 4, 2019 | 9.8 | 59 | NO | NO |
CVE-2020-12027MEDIUM All versions of FactoryTalk View SE disclose the hostnames and file paths for certain files within the system. A remote, authenticated attacker may be able to leverage this informa | Jul 20, 2020 | 4.3 | 55 | NO | YES |
CVE-2020-12029HIGH All versions of FactoryTalk View SE do not properly validate input of filenames within a project directory. A remote, unauthenticated attacker may be able to execute a crafted file | Jul 20, 2020 | 7.8 | 55 | NO | YES |
Signals from CVEs in this vendor scope (341 CVEs).
An overview of all social media posts that mention a CVE ID that affects a product developed by Rockwellautomation.
Media articles that mention a CVE ID that affects a product developed by Rockwellautomation — matched by CVE ID, not by vendor name.