CVE-2021-27476

OS COMMAND INJECTION CWE-78
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.

Read more: Critical Vulnerabilities Found in Rockwell FactoryTalk AssetCentre

Risk Information

  • CVE ID
  • CVE-2021-27476
  • Vendor
  • Rockwell Automation
  • Product
  • FactoryTalk AssetCentre
  • CVSS v3
  • 10