CVE-2021-27476
OS COMMAND INJECTION CWE-78
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Read more: Critical Vulnerabilities Found in Rockwell FactoryTalk AssetCentre
Risk Information
- CVE ID
- CVE-2021-27476
- Vendor
- Rockwell Automation
- Product
- FactoryTalk AssetCentre
- CVSS v3
- 10