CVE-2021-27476: Rockwell Automation FactoryTalk AssetCentre OS Command Injection
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
Affected Software
Remediation
Information
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2021-27476?
CVE-2021-27476 has been rated as a high severity vulnerability due to the potential for OS command injection.
How do I fix CVE-2021-27476?
To mitigate CVE-2021-27476, users should upgrade to a version of Rockwell Automation FactoryTalk AssetCentre that is newer than v10.00.
Who is affected by CVE-2021-27476?
CVE-2021-27476 affects users of Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
What type of vulnerability is CVE-2021-27476?
CVE-2021-27476 is classified as an OS command injection vulnerability.
Can CVE-2021-27476 be exploited remotely?
Yes, CVE-2021-27476 can be exploited by remote, unauthenticated attackers.