CVE-2021-27462
CRITICALRockwell Automation FactoryTalk AssetCentre <10.00 - Open Redirect
Title source: llmDescription
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
References (2)
Scores
CVSS v3
10.0
EPSS
0.0011
EPSS Percentile
29.5%
Attack Vector
NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Classification
CWE
CWE-502
Status
published
Affected Products (1)
rockwellautomation/factorytalk_assetcentre
< 10.00
Timeline
Published
Mar 23, 2022
Tracked Since
Feb 18, 2026