Critical severity10.0NVD Advisory· Published Mar 23, 2022· Updated Jun 17, 2026
CVE-2021-27472
CVE-2021-27472
Description
A vulnerability exists in the RunSearch function of SearchService service in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier, which may allow for the execution of remote unauthenticated arbitrary SQL statements.
AI Insight
LLM-synthesized narrative grounded in this CVE's description and references.
Affected products
3cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*:*+ 2 more
- cpe:2.3:a:rockwellautomation:factorytalk_assetcentre:*:*:*:*:*:*:*:*range: <=10.00
- (no CPE)range: <=10.00
- (no CPE)range: unspecified
Patches
Vulnerability mechanics
References
2- idp.rockwellautomation.com/adfs/ls/idpinitiatedsignon.aspxnvdPermissions RequiredVendor Advisory
- www.cisa.gov/uscert/ics/advisories/icsa-21-091-01nvdMitigationThird Party AdvisoryUS Government Resource
News mentions
0No linked articles in our index yet.