CVE-2021-27466
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data.
Does this matter?
High impact if exploited, but EPSS currently rates exploitation as unlikely (3.89%). Schedule it in the normal patch cycle and watch for a rise in EPSS or a public exploit.
Description
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in FactoryTalk AssetCentre.
- CVSS 3.1
- 9.8 CRITICALCVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H
- EPSS
- 3.89% probability · 90th percentile
- CISA KEV
- Not listed
- Weakness
- CWE-502
- Affected
- rockwellautomation/factorytalk assetcentre
- Source
- ics-cert@hq.dhs.gov
References
- https://idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspx?RelayState=RPID%3Drockwellautomation.custhelp.com%26RelayState%3Danswers%2Fanswer_view%2Fa_id%2F1130831Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01Third Party Advisory, US Government Resource
- https://idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspx?RelayState=RPID%3Drockwellautomation.custhelp.com%26RelayState%3Danswers%2Fanswer_view%2Fa_id%2F1130831Permissions Required, Vendor Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01Third Party Advisory, US Government Resource
Source: NVD record, EPSS from FIRST.org, KEV from CISA. Refreshed daily.