CVE-2021-27460

Severity CVSS v4.0:
Pending analysis
Type:
CWE-502 Deserialization of Untrusted Dat
Publication date:
23/03/2022
Last modified:
29/03/2022

Description

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, unauthenticated attacker to gain full access to the FactoryTalk AssetCentre main server and all agent machines.

Vulnerable products and versions

CPE From Up to
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*:* 10.00 (including)