CVE-2021-27466: Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27466?
CVE-2021-27466 has been rated as a high severity vulnerability that allows remote, unauthenticated attackers to execute arbitrary commands.
How do I fix CVE-2021-27466?
To mitigate CVE-2021-27466, upgrade Rockwell Automation FactoryTalk AssetCentre to a version later than 10.00 that addresses this vulnerability.
What impact does CVE-2021-27466 have on affected systems?
CVE-2021-27466 can lead to unauthorized remote code execution on systems running affected versions of FactoryTalk AssetCentre.
Who is affected by CVE-2021-27466?
CVE-2021-27466 affects users of Rockwell Automation FactoryTalk AssetCentre version 10.00 and earlier.
Is there a workaround for CVE-2021-27466?
Currently, there are no known workarounds for CVE-2021-27466, thus updating the software is the recommended action.