Vulnerability Information
Although we use advanced large model technology, its output may still contain inaccurate or outdated information.Shenlong tries to ensure data accuracy, but please verify and judge based on the actual situation.
Vulnerability Title
Rockwell Automation FactoryTalk AssetCentre OS Command Injection
Vulnerability Description
A vulnerability exists in the SaveConfigFile function of the RACompare Service, which may allow for OS command injection. This vulnerability may allow a remote, unauthenticated attacker to execute arbitrary commands in Rockwell Automation FactoryTalk AssetCentre v10.00 and earlier.
CVSS Information
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:C/C:H/I:N/A:H
Vulnerability Type
OS命令中使用的特殊元素转义处理不恰当(OS命令注入)
Vulnerability Title
Rockwell Automation FactoryTalk AssetCentre 操作系统命令注入漏洞
Vulnerability Description
Rockwell Automation FactoryTalk AssetCentre是美国罗克韦尔(Rockwell Automation)公司的一个应用系统。提供集中式工具,用于保护,管理,版本控制,跟踪和报告整个工厂中与自动化相关的资产信息 Rockwell Automation FactoryTalk AssetCentre 存在操作系统命令注入漏洞,该漏洞允许远程、未经身份验证的攻击者在FactoryTalk资产中心执行任意命令。
CVSS Information
N/A
Vulnerability Type
N/A