Vulnerability Details CVE-2021-27470
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
Exploit prediction scoring system (EPSS) score
EPSS Score 0.004
EPSS Ranking 59.0%
CVSS Severity
CVSS v3 Score 10.0
CVSS v2 Score 7.5
Products affected by CVE-2021-27470
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:-
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:5.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:6.10.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:7.10.01
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:8.00.00
-
cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:9.00.00