VendorsRockwell Automationconnected_components_workbenchall versions
Vulnerabilities

Rockwell Automation Connected Components Workbench

Ranked by severity, then by exploit likelihood. Click a CVE ID for its full record.

6CVEs
CVE-2021-27475
Rockwell Automation Connected Components Workbench Deserialization of Untrusted Data
Published 2022-03-23 · Modified
8.6EPSS 0.030
CVE-2021-27471
Rockwell Automation Connected Components Workbench Path Traversal
Published 2022-03-23 · Modified
8.6EPSS 0.029
CVE-2021-27473
Rockwell Automation Connected Components Workbench Improper Input Validation
Published 2022-03-23 · Modified
8.2EPSS 0.008
CVE-2014-5424
Rockwell Automation Connected Components Workbench (CCW) before 7.00.00 allows remote attackers to cause a denial of service (application crash) or possibly execute arbitrary code via an invalid property value to an ActiveX control that was built with an outdated compiler.
Published 2014-11-14 · Modified
7.5EPSS 0.110
CVE-2017-5176
A DLL Hijack issue was discovered in Rockwell Automation Connected Components Workbench (CCW). The following versions are affected: Connected Components Workbench - Developer Edition, v9.01.00 and earlier: 9328-CCWDEVENE, 9328-CCWDEVZHE, 9328-CCWDEVFRE, 9328-CCWDEVITE, 9328-CCWDEVDEE, 9328-CCWDEVESE, and 9328-CCWDEVPTE; and Connected Components Workbench - Free Standard Edition (All Supported Languages), v9.01.00 and earlier. Certain DLLs included with versions of CCW software can be potentially hijacked to allow an attacker to gain rights to a victim's affected personal computer. Such access rights can be at the same or potentially higher level of privileges as the compromised user account, including and up to computer administrator privileges.
Published 2017-05-19 · Modified
7.0EPSS 0.005
CVE-2022-1018
ICSA-22-088-01 Rockwell Automation ISaGRAF
Published 2022-04-01 · Modified
5.5EPSS 0.022