CVE-2021-27476

CRITICAL

Rockwell Automation FactoryTalk AssetCentre <10.00 - Command Injection

Title source: llm
STIX 2.1

Description

A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.

References (2)

Core 2
Core References
Mitigation, Third Party Advisory, US Government Resource x_refsource_confirm
https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01

Scores

CVSS v3 10.0
EPSS 0.0003
EPSS Percentile 9.9%
Attack Vector NETWORK
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H

CISA SSVC

Vulnrichment
Exploitation none
Automatable yes
Technical Impact partial

Details

CWE
CWE-78
Status published
Products (1)
rockwellautomation/factorytalk_assetcentre < 10.00
Published Mar 23, 2022
Tracked Since Feb 18, 2026