Filtered by vendor Rockwellautomation Subscriptions
Filtered by product Studio 5000 Simulation Interface Subscriptions
Total 2 CVE
CVE Vendors Products Updated CVSS v3.1
CVE-2025-11696 1 Rockwellautomation 1 Studio 5000 Simulation Interface 2025-11-12 N/A
A local server-side request forgery (SSRF) security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to trigger outbound SMB requests, enabling the capture of NTLM hashes.
CVE-2025-11697 1 Rockwellautomation 1 Studio 5000 Simulation Interface 2025-11-12 N/A
A local code execution security issue exists within Studio 5000® Simulation Interface™ via the API. This vulnerability allows any Windows user on the system to extract files using path traversal sequences, resulting in execution of scripts with Administrator privileges on system reboot.