CRITICAL🇵🇱 Wersja polska

CVE-2021-27466

CVSS 10.0v3.1pub. 2022-03-23upd. 2024-11-21

A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.

CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
  • Rockwellautomation Factorytalk Assetcentre

    APP
    Rockwellautomation
    ≤ 10.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassDeserialization
CWE
References

Related vulnerabilities

CVE-2025-0477CRITICAL9.3PL ✓same product

Słabe szyfrowanie haseł w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27464CRITICAL10.0PL ✓same product

SQLi bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27468CRITICAL10.0PL ✓same product

SQL Injection bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27470CRITICAL10.0PL ✓same product

RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre

CVE-2021-27462CRITICAL10.0PL ✓same product

RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre