CVE-2021-27474
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
Scoring
- Severity
- CRITICAL
- CVSS base score
- 10
- CVSS vector
- CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
- EPSS probability
- 0.09%
- CWE
- CWE-676
- Published
- 2022-03-23
- Last modified
- 2026-03-13
Affected products
- Rockwell Automation FactoryTalk AssetCentre
Weakness type
Related vulnerabilities
- CVE-2025-14601 — vsDesk Task Scheduler OS Command Injection
- CVE-2026-14501 — Use of Potentially Dangerous Functionthat in IBM Db2 Genius Hub
- CVE-2026-54499 — Stanza: Remote Code Execution via Unsafe Pickle Deserialization in Model Loaders
- CVE-2025-67604 — A use of potentially dangerous function vulnerability in Fortinet FortiAnalyzer 7.6.0 through...
- CVE-2025-65117 — AVEVA Process Optimization Use of Potentially Dangerous Function
- CVE-2024-50307 — Use of potentially dangerous function issue exists in Chatwork Desktop Application (Windows)...
- CVE-2024-38434 — Unitronics Vision PLC - CWE-676: Use of Potentially Dangerous Function
- CVE-2022-39063 — When Open5GS UPF receives a PFCP Session Establishment Request, it stores related values for...