Fiche vulnérabilité
CVE-2021-27474 : faille critique Rockwell Automation FactoryTalk… (CVSS 10.0)
Description
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
En bref
- Sévérité
- Critique (CVSS 10.0)
- Vecteur CVSS
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
- Exploitation active
- Non signalée par la CISA
- Publication
- 23 mars 2022
- Dernière mise à jour
- 16 avr. 2025
Produits concernés
- Rockwell Automation FactoryTalk AssetCentre
Correctif et mesures
Rockwell Automation encourages users of the affected versions of FactoryTalk AssetCentre to update to AssetCentre v11 (or above) to addresses these vulnerabilities. For more information about these vulnerabilities and mitigations please see Rockwell Automation’s publication KnowledgeBase ID: PN1559