« Volver al listado

Rockwellautomation

Rockwellautomation Factorytalk Assetcentre: vulnerabilidades y CVE

Rockwellautomation Factorytalk Assetcentre tiene 12 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 9 son críticas y 0 figuran en el catálogo de explotación activa de CISA.

CVE12
Últimos 12 meses0
Críticas9
Explotadas activamente0

Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología

Últimas vulnerabilidades

CVESeveridadEPSSExplotación activaPublicadaDescripción
CVE-2025-0498Alta (7)0.38%—30 ene 2025
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to insecure storage of FactoryTalk® Security user tokens, which…
CVE-2025-0497Alta (7.3)0.33%—30 ene 2025
A data exposure vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to storing credentials in the configuration file of…
CVE-2025-0477Crítica (9.3)0.37%—30 ene 2025
An encryption vulnerability exists in all versions prior to V15.00.001 of Rockwell Automation FactoryTalk® AssetCentre. The vulnerability exists due to a weak encryption methodology and could allow a threat actor to…
CVE-2021-27476Crítica (9.8)4.1%—23 mar 2022
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in…
CVE-2021-27474Alta (7.5)1.6%—23 mar 2022
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier does not properly restrict all functions relating to IIS remoting services. This vulnerability may allow a remote, unauthenticated attacker to modify…
CVE-2021-27472Crítica (9.8)5.7%—23 mar 2022
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL…
CVE-2021-27470Crítica (9.8)3.8%—23 mar 2022
A deserialization vulnerability exists in how the LogService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated…
CVE-2021-27468Crítica (9.8)3.5%—23 mar 2022
The AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to execute…
CVE-2021-27466Crítica (9.8)3.9%—23 mar 2022
A deserialization vulnerability exists in how the ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote,…
CVE-2021-27464Crítica (9.8)3.5%—23 mar 2022
The ArchiveService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier exposes functions lacking proper authentication. This vulnerability may allow a remote, unauthenticated attacker to…
CVE-2021-27462Crítica (9.8)3.8%—23 mar 2022
A deserialization vulnerability exists in how the AosService.rem service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier verifies serialized data. This vulnerability may allow a remote, unauthenticated…
CVE-2021-27460Crítica (9.8)3.2%—23 mar 2022
Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier components contain .NET remoting endpoints that deserialize untrusted data without sufficiently verifying that the resulting data will be valid. This…

🎯 Cómo se explota (técnicas ATT&CK)

  1. T1552 Unsecured Credentials2
  2. T1068 Exploitation for Privilege Escalation1
  3. T1190 Exploit Public-Facing Application1
  4. T1203 Exploitation for Client Execution1
  5. T1552.001 Credentials In Files1

Número de CVE de esta tecnología asignadas a cada técnica de explotación o de impacto principal.

Otros productos de Rockwellautomation