No Result
View All Result
Global Finances Daily
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers
  • Login
Global Finances Daily
No Result
View All Result
Home Protection

Organizations Informed of Over a Dozen Vulnerabilities in Rockwell Automation Products

May 14, 2023
in Protection
0
Rockwell Automation cybersecurity


Rockwell Automation customers have been informed this week about potentially serious vulnerabilities found and patched in several products. The timing coincides with reports of an investigation conducted by the US into the potential cyber risks associated with the automation giant’s operations in China.

Rockwell Automation published six new security advisories this week (registration required) and four of them have also been distributed by the US Cybersecurity and Infrastructure Security Agency (CISA). The advisories describe a total of more than a dozen vulnerabilities. 

One advisory warns organizations that Kinetix 5500 industrial control routers manufactured between May 2022 and January 2023 — specifically devices running firmware version 7.13 — have Telnet and FTP ports open by default, which could allow hackers to access the device. This critical vulnerability is tracked as CVE-2023-1834 and it has been patched with the release of firmware version 7.14. 

Two critical flaws have been found in Rockwell Automation’s PanelView 800 graphics terminals. The security holes are related to the WolfSSL component and they could lead to a heap buffer overflow, but devices are only impacted if the email feature is enabled in the project file — the feature is disabled by default.

Three high-severity buffer overflows, which can allow an attacker to commit or execute unauthorized code, have been found in the Arena event simulation and automation software.

The company’s ThinManager software management platform is affected by an issue related to ciphers. A malicious actor could leverage the weakness to decrypt traffic between the client and server API.

One of the two advisories that were published by Rockwell but were not picked up by CISA describes a cross-site request forgery in FactoryTalk Vantagepoint. The flaw can be exploited to impersonate a legitimate user by getting the target to click on a malicious link. 

Advertisement. Scroll to continue reading.

The second advisory informs customers about 10 cross-site scripting (XSS) vulnerabilities in some ArmorStart ST distributed motor controllers that can be used to view and modify sensitive data in the web interface or make it unavailable. User interaction is required for exploitation.

Rockwell Automation’s advisories now include an entry for each vulnerability specifying whether the bug is included in CISA’s Known Exploited Vulnerabilities (KEV) catalog. None of the flaws described in the Thursday advisories are included. 

Earlier this week, The Wall Street Journal reported that several US government departments are investigating Rockwell’s operations at a facility in Dalian, China, where employees might have access to information that could be used to compromise the systems of the company’s customers.

There has been some concern that those employees could find vulnerabilities in Rockwell software and exploit them in zero-day attacks aimed at systems in the United States.

CISA has published over a dozen security advisories describing Rockwell Automation flaws in the past year. CISA’s advisories inform organizations about more than 30 vulnerabilities affecting Rockwell products, including many rated ‘critical’ or ‘high’.

Related: New Vulnerabilities Allow Stuxnet-Style Attacks Against Rockwell PLCs

Related: Several DoS, Code Execution Vulnerabilities Found in Rockwell Automation Controllers

Related: Flaws in Rockwell Automation Product Expose Engineering Workstations to Attacks

Editorial Team

Editorial Team

Related Posts

The Philips Wi-Fi Smart Lock with Handle Is 35% Off for Amazon's Big Spring Sale
Protection

The Philips Wi-Fi Smart Lock with Handle Is 35% Off for Amazon’s Big Spring Sale

April 1, 2026
This Streamlined 'Nothing' Phone Is $200 Off During Amazon's Big Spring Sale
Protection

This Streamlined ‘Nothing’ Phone Is $200 Off During Amazon’s Big Spring Sale

April 1, 2026
These Are the Best Deals on Sneakers During Amazon's Big Spring Sale
Protection

These Are the Best Deals on Sneakers During Amazon's Big Spring Sale

April 1, 2026
The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘The Boys’
Protection

The Best Books, Movies, Video Games, and Podcasts to Check Out After Watching ‘The Boys’

April 1, 2026
These Are the Best Last-Minute Deals on Smart Glasses for Amazon's Big Spring Sale
Protection

These Are the Best Last-Minute Deals on Smart Glasses for Amazon’s Big Spring Sale

March 31, 2026
These Gym Bag Essentials Are Under $25 During Amazon's Big Spring Sale
Protection

These Gym Bag Essentials Are Under $25 During Amazon’s Big Spring Sale

March 31, 2026
Load More
Next Post
Investors predict ‘imminent’ US high-yield bond sell off

Investors predict ‘imminent’ US high-yield bond sell off

Popular News

  • Bitcoin ETFs extend outflow streak to sixth day even as BTC reclaims $103k

    Will Bitcoin price rally as Trump pushes for ceasefire in ongoing U.S.–Iran war?

    0 shares
    Share 0 Tweet 0
  • Workday’s stock dives as earnings reveal the cost of competing in AI

    0 shares
    Share 0 Tweet 0
  • China’s Fragile Recovery Keeps Policymakers on Alert

    0 shares
    Share 0 Tweet 0
  • How to Contact Hilton Customer Service

    0 shares
    Share 0 Tweet 0
  • The 14 Best Beaches in Europe for Doing It All or Absolutely Nothing

    0 shares
    Share 0 Tweet 0

Latest News

Binance founder’s attorney denies pay-to-play speculation after CZ’s pardon

CZ says quantum won’t kill crypto, calls for calm post‑quantum upgrade

April 1, 2026
0

Summary Binance founder Changpeng “CZ” Zhao said crypto systems only need to upgrade to post‑quantum algorithms to handle quantum computers...

Here are 12 top tech-themed stock picks from UBS analysts

Here are 12 top tech-themed stock picks from UBS analysts

April 1, 2026
0

The investment bank has “high conviction” in Amazon’s growth potential — with AWS estimates that are far above what investors may...

The Philips Wi-Fi Smart Lock with Handle Is 35% Off for Amazon's Big Spring Sale

The Philips Wi-Fi Smart Lock with Handle Is 35% Off for Amazon’s Big Spring Sale

April 1, 2026
0

We may earn a commission from links on this page. Deal pricing and availability subject to change after time of...

Jack Dorsey’s Block pitches mini-AGI vision weeks after cutting nearly half its workforce

Jack Dorsey’s Block pitches mini-AGI vision weeks after cutting nearly half its workforce

April 1, 2026
0

Block is pushing its AI strategy further, with CEO Jack Dorsey and lead independent director Roelof Botha outlining a plan...

Global Finances Daily

Welcome to Global Finances Daily, your go-to source for all things finance. Our mission is to provide our readers with valuable information and insights to help them achieve their financial goals and secure their financial future.

Subscribe

  • About Us
  • Contact
  • Privacy Policy
  • Terms of Use
  • Editorial Process

© 2025 All Rights Reserved - Global Finances Daily.

No Result
View All Result
  • Alternative Investments
  • Crypto
  • Financial Markets
  • Investments
  • Lifestyle
  • Protection
  • Retirement
  • Savings
  • Work & Careers

© 2025 All Rights Reserved - Global Finances Daily.

Welcome Back!

Login to your account below

Forgotten Password?

Retrieve your password

Please enter your username or email address to reset your password.

Log In
This website uses cookies. By continuing to use this website you are giving consent to cookies being used. Visit our Privacy and Cookie Policy.