Aller au contenu

Fiche vulnérabilité

CVE-2021-27474 : faille critique Rockwell Automation FactoryTalk… (CVSS 10.0)

Description

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.

En bref

Sévérité
Critique (CVSS 10.0)
Vecteur CVSS
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Exploitation active
Non signalée par la CISA
Publication
23 mars 2022
Dernière mise à jour
16 avr. 2025

Produits concernés

  • Rockwell Automation FactoryTalk AssetCentre

Correctif et mesures

Rockwell Automation encourages users of the affected versions of FactoryTalk AssetCentre to update to AssetCentre v11 (or above) to addresses these vulnerabilities. For more information about these vulnerabilities and mitigations please see Rockwell Automation’s publication KnowledgeBase ID: PN1559

Références

Rechercher une autre vulnérabilité dans la base CVE