CVE-2021-27474: Rockwell Automation FactoryTalk AssetCentre Use of Potentially Dangerous Function
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27474?
CVE-2021-27474 has a high severity rating due to its potential for remote, unauthenticated access and data modification.
How do I fix CVE-2021-27474?
To fix CVE-2021-27474, users should immediately update to a patched version of Rockwell Automation FactoryTalk AssetCentre that addresses this vulnerability.
What systems are affected by CVE-2021-27474?
CVE-2021-27474 affects Rockwell Automation FactoryTalk AssetCentre version 10.00 and earlier.
What type of attack does CVE-2021-27474 enable?
CVE-2021-27474 enables remote attackers to modify sensitive data without authentication.
Is there a workaround for CVE-2021-27474?
For CVE-2021-27474, it is recommended to limit access to IIS remoting services as a temporary measure until a patch can be applied.