A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
References
Link | Resource |
---|---|
https://www.cisa.gov/uscert/ics/advisories/icsa-21-091-01 | Mitigation Third Party Advisory US Government Resource |
https://idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspx?RelayState=RPID%3Drockwellautomation.custhelp.com%26RelayState%3Danswers%2Fanswer_view%2Fa_id%2F1130831 | Permissions Required Vendor Advisory |
Configurations
Information
Published : 2022-03-23 13:15
Updated : 2022-03-29 12:15
NVD link : CVE-2021-27472
Mitre link : CVE-2021-27472
JSON object : View
CWE
CWE-89
Improper Neutralization of Special Elements used in an SQL Command ('SQL Injection')
Products Affected
rockwellautomation
- factorytalk_assetcentre