The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
CVSS Vector
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:HRockwellautomation Factorytalk Assetcentre
APPRockwellautomation≤ 10.00
🔵
CHECK WITH VENDOR
No clear patch data available. Check vendor references.
Tags
Auth BypassSQLi
Related vulnerabilities
CVE-2025-0477CRITICAL9.3PL ✓same product
Słabe szyfrowanie haseł w Rockwell Automation FactoryTalk AssetCentre
CVE-2021-27464CRITICAL10.0PL ✓same product
SQLi bez uwierzytelnienia w Rockwell Automation FactoryTalk AssetCentre
CVE-2021-27466CRITICAL10.0PL ✓same product
RCE przez niebezpieczną deserializację w Rockwell FactoryTalk AssetCentre
CVE-2021-27470CRITICAL10.0PL ✓same product
RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre
CVE-2021-27462CRITICAL10.0PL ✓same product
RCE przez deserializację w Rockwell Automation FactoryTalk AssetCentre