Updated just now · 68 advisories
An attacker with admin credentials could read or delete arbitrary files on your ISE system, potentially including authentication databases, configuration files, or operational records critical to network access control.
An attacker could modify PLC program logic or firmware during development or deployment, potentially altering setpoints, disabling safeties, or corrupting control sequences that govern critical processes in water treatment, power distribution, or manufacturing facilities.
An attacker could read or modify files outside the intended application directory on ThinManager servers, potentially exposing sensitive configuration data, credentials, or scripts that control terminal access and device management for industrial HMI systems.
A buffer overflow in Rockwell PLCs could allow an attacker to execute arbitrary code on the controller, potentially disrupting production processes, altering safety logic, or causing uncontrolled equipment operation.
An attacker with network access to these Ethernet communication modules can send specially crafted packets that cause the device to stop responding, disrupting communication with PLCs and other devices on your industrial network until the module is manually reset.
An attacker could send specially crafted network messages to a 1734 POINT I/O module, causing it to stop responding and halt I/O operations until it is manually rebooted. This would interrupt any process that depends on those input or output signals.
An attacker can remotely crash the 1718-AENTR/1719-AENTR Ethernet adapter, forcing a manual restart and causing loss of network communication with connected control systems until the device recovers.
An attacker can remotely disable the Flex 5000 Adapter, causing it to stop processing communications from connected devices. This would interrupt data flow between your control systems and field devices, potentially halting production or affecting real-time process monitoring.
An attacker who reaches your FactoryTalk Services Platform could bypass authentication and gain unauthorized access to manufacturing operations data and control systems, potentially allowing them to view sensitive production information or interfere with connected machinery.
An attacker with access to FactoryTalk DataMosaix Private Cloud could inject malicious code that executes when other authorized users view affected pages, potentially allowing credential theft or unauthorized commands to be issued within the system.
An attacker with network access to Arena could trigger a memory corruption flaw that causes the application to crash or potentially execute arbitrary code, disrupting engineering workflow and plant modeling operations.
The communications module cannot validate whether network certificates have been revoked, allowing an attacker with a compromised certificate to maintain unauthorized network connections to your PLC or network. This could enable persistent access to alter control logic or monitor production operations.
An attacker with a local user account on a Windows workstation or server could exploit this vulnerability to run commands with system-level privileges, potentially allowing them to modify critical configurations, disable security controls, or compromise the integrity of the system.
An attacker with local access to a Windows system could read sensitive information from uninitialized memory in the SMB service, potentially exposing credentials or configuration data used by network operations.
An attacker with local access to a Windows system could read sensitive kernel memory information that is normally restricted, potentially exposing system internals or security-related data useful for further attacks.
A user with local access to a Windows Server could exploit improper access control to gain administrator privileges, allowing them to modify system settings, stop services, or alter plant control logic running on that server.
An attacker with local access to a Windows machine could exploit an integer underflow in NTFS to run arbitrary code with elevated privileges, potentially compromising the entire system and any connected networks or control systems.
An attacker with local access to a Windows workstation or server could escalate privileges from a standard user account to administrator or system level, potentially allowing them to control the entire machine and any connected OT/ICS equipment.
A local attacker with user access could exploit a buffer overflow in NTFS to run commands with system privileges, potentially disrupting operations or gaining persistence on control system workstations or servers.
An attacker with a low-privilege account on your Windows server or workstation could gain administrative access, potentially allowing them to modify system settings, install persistent malware, or access sensitive data across the entire machine.
A local user with standard privileges could overflow a buffer in NTFS and gain administrative access to the Windows system, potentially allowing full control of the machine and any connected industrial equipment or data it manages.
A local attacker with no special privileges could run arbitrary code on a Windows computer or server through a heap buffer overflow in NTFS, potentially compromising system integrity and data confidentiality.
An attacker on the network can exploit the Windows DHCP client to gain administrative privileges on your servers or workstations without using valid credentials, potentially taking full control of the system.
An attacker with domain user credentials could execute arbitrary code on your domain controller or domain-joined servers, potentially compromising your entire Active Directory infrastructure and allowing them to modify user accounts, permissions, or plant persistent backdoors.
An attacker with DHCP server access credentials could exploit a buffer overflow to run arbitrary code on a Windows server that provides DHCP to your network, potentially disrupting IP address assignment or compromising the server itself.
A logged-in user could exploit a buffer overflow in Windows NTFS to run code with the privileges of that user account, potentially enabling lateral movement within your network or persistence on compromised systems.
An attacker with local access to a Windows system could read kernel memory to bypass a security feature, potentially enabling privilege escalation or other attacks. This is a local threat and does not directly impact remote operations.
An attacker with local access to a Windows server or workstation could gain system-level privileges, allowing them to install malware, modify system configurations, or disrupt operations on that machine.
An attacker could read sensitive data from system memory through RDP without valid credentials, potentially exposing configuration details, credentials, or operational data from HMI systems and engineering workstations that use RDP for remote access.
An attacker with valid domain credentials could crash or hang your Active Directory Domain Services, making domain services unavailable and disrupting authentication, user login, and access to networked systems and equipment.
An attacker with local access to a Windows Server or Windows 11 system running Hyper-V could execute code with elevated privileges, potentially compromising the entire host system and any virtual machines it runs.
An attacker with standard user credentials on your Windows or Windows Server system can escalate to higher privileges on the local machine, potentially gaining administrative control of the system.
An attacker who connects to a Windows machine with RDP enabled could read sensitive memory information from the RDP service, potentially revealing credentials, encryption keys, or other confidential data without authentication. This creates a risk of lateral movement or further compromise.
An attacker on your local network (adjacent network segment) could execute arbitrary code on affected Windows systems by exploiting a race condition in the TCP/IP stack, potentially gaining control of servers or workstations used in your operations.
An attacker with local access to an affected Windows system could read sensitive information from memory that should have been cleared, potentially exposing credentials or other confidential data. This is a local-only vulnerability with limited immediate operational impact on industrial systems.
An attacker can send a specially crafted network request to Windows Active Directory, causing it to enter an infinite loop that makes domain authentication and directory services unavailable. This would prevent users and systems from logging in or communicating with domain controllers, disrupting plant operations dependent on networked access control.
A user with a standard local account on your Windows workstation or server could gain administrative privileges through a use-after-free flaw in the Win32k subsystem, potentially compromising the entire system and any connected OT networks.
A user with local access to a Windows system could exploit this race condition to gain administrative privileges, allowing them to install malware, modify system settings, or access sensitive data on that machine.
An attacker with local access to a domain-joined Windows server or workstation can gain elevated privileges and take control of critical infrastructure systems. In water or electric utilities, this could allow unauthorized changes to supervisory systems, PLCs, or historian servers that manage pumps, generators, or other essential equipment.
A logged-in user on an affected Windows system could exploit a heap buffer overflow in the graphics subsystem to gain elevated privileges, allowing them to install software, modify settings, or access sensitive data that requires admin rights.
A user with local access to a Windows system (such as an operator at an HMI or engineering workstation) could exploit this flaw to gain administrative privileges, allowing them to modify SCADA configurations, alter process logic, or disable monitoring.
An attacker with physical access to a Windows workstation or server could escalate privileges to run commands at the highest system level, potentially taking control of critical engineering systems or data on that machine.
An attacker could send a specially crafted network packet to a Windows machine running Remote Desktop Client, causing a heap buffer overflow that allows arbitrary code execution with the privileges of the user running the client.
An attacker could send malicious network packets to crash Windows servers running IKE (used for VPN and remote access), disrupting remote connectivity and potentially interrupting operations that depend on remote access or VPN tunnel availability.
An attacker with a local user account on a Hyper-V host can exploit a memory issue to run code with system-level privileges, potentially allowing them to control virtual machines or the host itself.
An attacker can crash AD FS services, preventing users and systems from authenticating through your federation infrastructure. This stops single sign-on across your organization and may block access to critical systems and applications.
An attacker on your network can send specially crafted requests to AD FS to crash the service, blocking employee login and potentially disrupting authentication for connected systems and applications.
A local user on a Windows system could read sensitive TCP/IP stack memory, potentially exposing network configuration details or other system information.
An attacker with local access to a Windows 11 system could escalate their privileges to run code with higher permissions, potentially allowing them to modify system settings, access sensitive data, or interfere with HMI/operator systems and engineering workstations used to manage industrial equipment.
An attacker with administrative or DNS management credentials could exploit a use-after-free flaw in Windows DNS Server to run arbitrary code on your DNS server, potentially disrupting name resolution across your network or compromising other systems that rely on DNS.