CVE-2021-27470: Rockwell Automation FactoryTalk AssetCentre Deserialization of Untrusted Data
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27470?
CVE-2021-27470 has been classified as a high severity vulnerability due to its potential to allow remote command execution.
How do I fix CVE-2021-27470?
To mitigate CVE-2021-27470, it is recommended to update Rockwell Automation FactoryTalk AssetCentre to a version later than v10.00.
What systems are affected by CVE-2021-27470?
CVE-2021-27470 affects Rockwell Automation FactoryTalk AssetCentre version 10.00 and earlier.
Can CVE-2021-27470 be exploited remotely?
Yes, CVE-2021-27470 can be exploited by remote, unauthenticated attackers.
What type of vulnerability is CVE-2021-27470?
CVE-2021-27470 is a deserialization vulnerability that affects the verification of serialized data.