CVE-2021-27460

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines.
Configurations

Configuration 1 (hide)

cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*:*

History

29 Mar 2022, 17:46

Type Values Removed Values Added
First Time Rockwellautomation factorytalk Assetcentre
Rockwellautomation
CPE cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*:*
CVSS v2 : unknown
v3 : unknown
v2 : 7.5
v3 : 9.8
CWE CWE-502
References (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01 - (CONFIRM) https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01 - Third Party Advisory, US Government Resource
References (CONFIRM) https://idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspx?RelayState=RPID%3Drockwellautomation.custhelp.com%26RelayState%3Danswers%2Fanswer_view%2Fa_id%2F1130831 - (CONFIRM) https://idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspx?RelayState=RPID%3Drockwellautomation.custhelp.com%26RelayState%3Danswers%2Fanswer_view%2Fa_id%2F1130831 - Permissions Required, Vendor Advisory

23 Mar 2022, 20:15

Type Values Removed Values Added
New CVE

Information

Published : 2022-03-23 20:15

Updated : 2023-12-10 14:22


NVD link : CVE-2021-27460

Mitre link : CVE-2021-27460

CVE.ORG link : CVE-2021-27460


JSON object : View

Products Affected

rockwellautomation

  • factorytalk_assetcentre
CWE
CWE-502

Deserialization of Untrusted Data