CVE-2021-27464: Rockwell Automation FactoryTalk AssetCentre SQL Injection
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27464?
CVE-2021-27464 is considered a critical vulnerability due to its potential to allow remote, unauthenticated attackers to execute arbitrary SQL statements.
How do I fix CVE-2021-27464?
To fix CVE-2021-27464, users should upgrade to a patched version of Rockwell Automation FactoryTalk AssetCentre beyond v10.00.
What types of attacks can be performed exploiting CVE-2021-27464?
Exploiting CVE-2021-27464 can lead to unauthorized access, data manipulation, and potential data exfiltration through arbitrary SQL execution.
Which versions of FactoryTalk AssetCentre are affected by CVE-2021-27464?
FactoryTalk AssetCentre versions v10.00 and earlier are affected by CVE-2021-27464.
Can CVE-2021-27464 be exploited from a local network?
Yes, CVE-2021-27464 can be exploited remotely, allowing attackers to target the system from outside the local network.