CVE-2021-27472: Rockwell Automation FactoryTalk AssetCentre SQL Injection
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27472?
CVE-2021-27472 has been assessed as a high severity vulnerability due to its potential for remote unauthenticated SQL statement execution.
How do I fix CVE-2021-27472?
To fix CVE-2021-27472, upgrade to a patched version of Rockwell Automation FactoryTalk AssetCentre that addresses this vulnerability.
What systems are affected by CVE-2021-27472?
CVE-2021-27472 affects Rockwell Automation FactoryTalk AssetCentre version 10.00 and earlier.
What type of attacks can exploit CVE-2021-27472?
CVE-2021-27472 can be exploited to execute arbitrary SQL statements remotely without authentication.
Is CVE-2021-27472 being actively exploited?
There are currently no known active exploits for CVE-2021-27472, but the vulnerability poses a significant risk.