Rockwell Automation Studio 5000 Logix Designer是美国Rockwell Automation基金会的一款自动化控制编程软件。 Rockwell Automation Studio 5000 Logix Designer存在授权问题漏洞,该漏洞源于配置文件授权错误,可能导致经过身份验证的用户修改应用程序内配置的外部工具路径。一旦利用,攻击者可将配置指向恶意可执行文件,导致任意用户与外部工具交互时执行任意代码。以下版本受到影响:V35.00版本、34.00版本、34
| Vendor | Product | Version Range | Status |
|---|---|---|---|
| Rockwell Automation | Studio 5000 Logix Designer | V35.00,34.00,34.01, 33.00,33.02, 32.00-32.04 and older |
affected |
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
| Vendor | Product | Affected Versions | CPE | Subscribe |
|---|---|---|---|---|
| Rockwell Automation | Studio 5000 Logix Designer | V35.00,34.00,34.01, 33.00,33.02, 32.00-32.04 and older | - |
|
| # | POC Description | Source Link | Shenlong Link |
|---|
No public POC found.
Login to generate AI POC| CVE-2025-12011 | 9.2 CRITICAL | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
| CVE-2026-10573 | 6.3 MEDIUM | 1734 POINT I/OTM - Denial of Service via Malformed Inputs on CIP Object |
| CVE-2026-8085 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8314 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-8313 | Rockwell Automation Arena® - Memory Corruption Vulnerability | |
| CVE-2026-9653 | 1756-EN2, 1756-EN3, and 1756-ENBT - Denial of Service via CIP Connection ID | |
| CVE-2026-9140 | 1718-AENTR/1719-AENTR - Denial of Service | |
| CVE-2026-10714 | Rockwell Automation FactoryTalk® Services Platform FTSP - Weak Authentication via JWT Vali | |
| CVE-2025-12012 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow | |
| CVE-2026-11917 | ThinManager® - Path Traversal via API | |
| CVE-2026-9108 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9128 | Studio 5000 Logix Designer® – Multiple Vulnerabilities | |
| CVE-2026-9636 | Rockwell Automation CompactLogix® 5380 ControlLogix® 5580 / 1756-EN4 Communications Module | |
| CVE-2026-9292 | Rockwell Automation FactoryTalk® DataMosaix™ Private Cloud - Stored Cross-Site Scripting | |
| CVE-2026-12659 | Rockwell Automation Flex 5000® Adapter - Denial of Service | |
| CVE-2025-11698 | CompactLogix ®, ControlLogix ®, Compact GuardLogix ® and GuardLogix ® Buffer Overflow |
No comments yet