CVE-2021-27474

USE OF POTENTIALLY DANGEROUS FUNCTION CWE-676
FactoryTalk AssetCentre does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.

Read more: Critical Vulnerabilities Found in Rockwell FactoryTalk AssetCentre

Risk Information

  • CVE ID
  • CVE-2021-27474
  • Vendor
  • Rockwell Automation
  • Product
  • FactoryTalk AssetCentre
  • CVSS v3
  • 10