Rockwell Automation FactoryTalk® Services Platform是美国Rockwell Automation基金会的一款工业控制服务平台。 Rockwell Automation FactoryTalk® Services Platform 6.60版本存在授权问题漏洞,该漏洞源于应用程序未验证JWT算法是否配置为RSA,允许攻击者设置算法为“none”并伪造令牌,导致经过身份验证的低权限用户可冒充任何授权用户,进而非法访问系统配置并授权其他系统。
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rockwell Automation | FactoryTalk® Services Platform | Version 6.60 |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | FactoryTalk® Services Platform | Version 6.60 | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12011 | 9.2 CRITICAL | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
| CVE-2026-10573 | 6.3 MEDIUM | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-8085 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8314 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8313 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-9653 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID | |
| CVE-2026-9140 | 1718-AENTR/1719-AENTR - Denial of Service | |
| CVE-2025-12012 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow | |
| CVE-2026-11917 | ThinManager® - Path Traversal via API | |
| CVE-2026-9108 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9128 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9636 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module | |
| CVE-2026-9292 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting | |
| CVE-2026-9127 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-12659 | Rockwell Automation Flex 5000® Adapter - Denial of Service | |
| CVE-2025-11698 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
No comments yet