Discover your next big idea at PACK EXPO Las Vegas this September
Experience a breakthrough in packaging & processing and transform your business with solutions from 2,300 suppliers spanning all industries.

Rockwell Reveals 10 Vulnerabilities in 3 Popular Products

Users are urged to implement best practices to mitigate the potential risks with FactoryTalk, PowerFlex and Arena Simulation.

Company issues three security advisories highlighting 10 vulnerabilities in its FactoryTalk, PowerFlex, and Arena Simulation products
Company issues three security advisories highlighting 10 vulnerabilities in its FactoryTalk, PowerFlex, and Arena Simulation products

Rockwell Automation recently issued three security advisories highlighting 10 vulnerabilities in its FactoryTalk, PowerFlex, and Arena Simulation products. The US Cybersecurity and Infrastructure Security Agency (CISA) has also echoed these advisories to inform organizations about the identified vulnerabilities within the industrial automation company's offerings.

Among the disclosed vulnerabilities, one advisory focused on six flaws within the Arena Simulation software. These included five high-severity arbitrary code execution vulnerabilities and one medium-severity information disclosure and denial-of-service (DoS) issue. Each vulnerability necessitates the user to open a malicious file to exploit it. Rockwell Automation credited the discovery of these vulnerabilities to ICS cybersecurity researcher Michael Heinzl, who is recognized for reporting critical vulnerabilities that often involve manipulating specifically crafted files. Heinzl's advisories elaborated on the exploitation methods involving customized DOE files reported to the vendor through CISA in November 2023.

Researched List: Engineering Services Firms
Looking for engineering services? Our curated list features 100+ companies specializing in civil, process, structural, and electrical engineering. Many also offer construction, design, and architecture services. Download to access company names, markets served, key services, contact information, and more!
Download Now
Researched List: Engineering Services Firms
Coding, Marking, and Labeling Innovations Report
Explore our editor-curated report featuring cutting-edge coding, labeling, and RFID innovations from PACK EXPO 2024. Discover high-speed digital printing, sustainable label materials, automated labeling systems, and advanced traceability solutions that are transforming packaging operations across industries.
Access Report
Coding, Marking, and Labeling Innovations Report