Vulnerabilities > Rockwellautomation

DATE CVE VULNERABILITY TITLE RISK
2022-03-23 CVE-2021-27460 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2022-03-23 CVE-2021-27462 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2022-03-23 CVE-2021-27464 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication.
network
low complexity
rockwellautomation CWE-89
critical
9.8
2022-03-23 CVE-2021-27466 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2022-03-23 CVE-2021-27468 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication.
network
low complexity
rockwellautomation CWE-89
critical
9.8
2022-03-23 CVE-2021-27470 Deserialization of Untrusted Data vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
network
low complexity
rockwellautomation CWE-502
critical
9.8
2022-03-23 CVE-2021-27471 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
The parsing mechanism that processes certain file types does not provide input sanitization for file paths.
local
low complexity
rockwellautomation CWE-22
8.6
2022-03-23 CVE-2021-27472 SQL Injection vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
network
low complexity
rockwellautomation CWE-89
critical
9.8
2022-03-23 CVE-2021-27473 Path Traversal vulnerability in Rockwellautomation Connected Components Workbench 12.00.00
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction.
local
low complexity
rockwellautomation CWE-22
8.2
2022-03-23 CVE-2021-27474 Unspecified vulnerability in Rockwellautomation Factorytalk Assetcentre 10.00
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services.
network
low complexity
rockwellautomation
7.5