CVE-2021-27462: Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27462?
CVE-2021-27462 is considered critical due to its potential for remote code execution by unauthenticated attackers.
How do I fix CVE-2021-27462?
To remediate CVE-2021-27462, upgrade to the latest version of Rockwell Automation FactoryTalk AssetCentre that addresses this vulnerability.
What software is affected by CVE-2021-27462?
CVE-2021-27462 affects Rockwell Automation FactoryTalk AssetCentre versions 10.00 and earlier.
Can CVE-2021-27462 be exploited remotely?
Yes, CVE-2021-27462 can be exploited remotely without authentication.
What kind of attack does CVE-2021-27462 enable?
CVE-2021-27462 enables attackers to execute arbitrary commands on the affected system.