Show filters
12 Total Results
Displaying 1-10 of 12
Sort by:
Attacker Value
Unknown

CVE-2025-0498

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal a token and, impersonate another user.
0
Attacker Value
Unknown

CVE-2025-0497

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, LogCleanUp, or ArchiveLogCleanUp packages.
0
Attacker Value
Unknown

CVE-2025-0477

Disclosure Date: January 30, 2025 (last updated January 31, 2025)
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to other users of the application.
0
Attacker Value
Unknown

CVE-2021-27476

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
Attacker Value
Unknown

CVE-2021-27474

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27472

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27470

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27468

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
Attacker Value
Unknown

CVE-2021-27466

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Attacker Value
Unknown

CVE-2021-27464

Disclosure Date: March 23, 2022 (last updated February 23, 2025)
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.