← Back to browse · API

CVE-2021-27474

Severity
CRITICAL
CVSS
10.0
EPSS
0.01612
Risk score
40.56
CISA KEV
No
PoC
No
Published
2022-03-23
Modified
2025-04-16
First seen
2026-08-07
Aliases
EUVD-2021-14228, GHSA-CG2F-J69H-XCX2
Products
Rockwell Automation:FactoryTalk AssetCentre unspecified ≤v10.00
Sources
euvd EUVD-2021-14228

Description

Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCentre.

References