- EPSS 0.03%
- Veröffentlicht 30.01.2025 18:15:33
- Zuletzt bearbeitet 30.01.2025 18:15:33
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which could allow a threat actor to steal...
CVE-2025-0497
- EPSS 0.02%
- Veröffentlicht 30.01.2025 18:15:32
- Zuletzt bearbeitet 30.01.2025 18:15:32
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of EventLogAttachmentExtractor, ArchiveExtractor, ...
CVE-2025-0477
- EPSS 0.06%
- Veröffentlicht 30.01.2025 18:15:31
- Zuletzt bearbeitet 30.01.2025 18:15:31
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to extract passwords belonging to oth...
CVE-2021-27472
- EPSS 0.09%
- Veröffentlicht 23.03.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:03
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
CVE-2021-27474
- EPSS 0.09%
- Veröffentlicht 23.03.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:03
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify sensitive data in FactoryTalk AssetCe...
CVE-2021-27476
- EPSS 0.03%
- Veröffentlicht 23.03.2022 20:15:09
- Zuletzt bearbeitet 21.11.2024 05:58:04
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk...
CVE-2021-27460
- EPSS 0.29%
- Veröffentlicht 23.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:02
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This vulnerability may allow a remote, una...
CVE-2021-27462
- EPSS 0.11%
- Veröffentlicht 23.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:02
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary ...
CVE-2021-27464
- EPSS 0.03%
- Veröffentlicht 23.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:02
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary SQL statements.
CVE-2021-27466
- EPSS 0.11%
- Veröffentlicht 23.03.2022 20:15:08
- Zuletzt bearbeitet 21.11.2024 05:58:02
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated attacker to execute arbitr...