CVE-2021-27468: Rockwell Automation FactoryTalk AssetCentre SQL Injection
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27468?
CVE-2021-27468 has a high severity rating due to its potential for remote exploitation by unauthorized users.
How do I fix CVE-2021-27468?
To fix CVE-2021-27468, update your Rockwell Automation FactoryTalk AssetCentre to a version later than 10.00 that includes proper authentication measures.
What are the risks associated with CVE-2021-27468?
The risks associated with CVE-2021-27468 include unauthorized execution of arbitrary SQL statements which can lead to data leakage or manipulation.
Which versions of FactoryTalk AssetCentre are affected by CVE-2021-27468?
CVE-2021-27468 affects Rockwell Automation FactoryTalk AssetCentre version 10.00 and earlier.
Can CVE-2021-27468 be exploited remotely?
Yes, CVE-2021-27468 can be exploited remotely by unauthenticated attackers due to the lack of proper authentication measures.