Rockwell Automation FactoryTalk AssetCentre SQL Injection
CVE-2021-27472
10CRITICAL
Key Information:
- Vendor
Rockwell Automation
- Status
- Vendor
- CVE Published:
- 23 March 2022
What is CVE-2021-27472?
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
Affected Version(s)
FactoryTalk AssetCentre <= unspecified