Show filters
273 Total Results
Displaying 111-120 of 273
Sort by:
Attacker Value
Unknown

CVE-2021-27476

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
Attacker Value
Unknown

CVE-2021-27475

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not limit the objects that can be deserialized. This vulnerability allows attackers to craft a malicious serialized object that, if opened by a local user in Connected Components Workbench, may result in remote code execution. This vulnerability requires user interaction to be successfully exploited.
Attacker Value
Unknown

CVE-2021-27474

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27473

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation Connected Components Workbench v12.00.00 and prior does not sanitize paths specified within the .ccwarc archive file during extraction. This type of vulnerability is also commonly referred to as a Zip Slip. A local, authenticated attacker can create a malicious .ccwarc archive file that, when opened by Connected Components Workbench, will allow the attacker to gain the privileges of the software. If the software is running at SYSTEM level, the attacker will gain admin level privileges. User interaction is required for this exploit to be successful.
Attacker Value
Unknown

CVE-2021-27472

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27471

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The parsing mechanism that processes certain file types does not provide input sanitization for file paths. This may allow an attacker to craft malicious files that, when opened by Rockwell Automation Connected Components Workbench v12.00.00 and prior, can traverse the file system. If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. User interaction is required for this exploit to be successful.
Attacker Value
Unknown

CVE-2021-27470

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27468

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27466

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27464

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.