CVE-2021-27472

CRITICAL

Rockwell Automation FactoryTalk AssetCentre <10.00 - SQL Injection

Title source: llm
STIX 2.1

Description

A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01

Scores

CVSS v3 10.0
EPSS 0.0009
EPSS Percentile 25.6%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-89
Status published
Products (1)
rockwellautomation/factorytalk_assetcentre < 10.00
Published Mar 23, 2022
Tracked Since Feb 18, 2026