PT-2022-9833 · Rockwell Automation · Factorytalk Assetcentre
Published
2022-03-23
·
Updated
2022-07-29
·
CVE-2021-27474
CVSS v3.1
10
Critical
| Vector | AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H |
Name of the Vulnerable Software and Affected Versions
Rockwell Automation FactoryTalk AssetCentre versions 10.00 and earlier
Description
The issue is related to improper restriction of functions related to IIS remoting services, which may allow a remote, unauthenticated attacker to modify sensitive data.
Recommendations
For versions 10.00 and earlier, update to a version later than 10.00 to resolve the issue.
Fix
Found an issue in the description? Have something to add? Feel free to write us 👾
Weakness Enumeration
Related Identifiers
Affected Products
Factorytalk Assetcentre