← Back to home
ICSA-13-095-02A  ·  Published 2025-06-06  ·  View on CISA ICS-CERT ↗

Rockwell Automation FactoryTalk and RSLinx Vulnerabilities

CVSS 10.0 CRITICAL

Remediations

  • Rockwell Automation’s recommendation to asset owners using FTSP or RSLinx CPR9 through CPR9-SR4 is to upgrade to CPR9-SR5 or newer. Rockwell Automation also recommends that all asset owners using FTSP or RSLinx CPR9-SR5 and newer should apply the correlating patch for the version they are using.
  • The patches and details pertaining to these vulnerabilities can be found at the following Rockwell Automation Security Advisory link (login is required): (https://rockwellautomation.custhelp.com/app/answers/detail/a_id/537599)
  • In addition, asset owners can find security information for other Rockwell Automation products at the Security Advisory Index page link below (login is required): (https://rockwellautomation.custhelp.com/app/answers/detail/a_id/54102)

Affected Vendors

Rockwell Automation

Affected Products (8)

Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR1
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR2
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR3
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR4
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR5
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR5.1
Rockwell Automation · FactoryTalk Services Platform and RSLinx Enterprise CPR9-SR6

Get alerted to advisories like this

OTWarden monitors CISA, BSI, Siemens, Rockwell and more — and emails you within 2 hours when your vendors are affected.

Start free trial Learn more