logo

Critical Vulnerabilities Found in Rockwell FactoryTalk AssetCentre

ID: 893c702e-28b9-51e6-b810-81b860c060b4

STIX ID: report--893c702e-28b9-51e6-b810-81b860c060b4

Feed Name: Claroty Team82

Threat Score
90/100

Date Published: 2023-10-31

Date Updated: 2026-04-17

Author: Amir Preminger; Sharon Brizinov

...
...

Claroty (Team82) disclosed nine critical CVSS‑10 vulnerabilities in Rockwell Automation's FactoryTalk AssetCentre (v10 and earlier), including multiple deserialization issues, SQL injection, and an OS command injection. These pre‑authentication flaws could allow unauthenticated remote code execution on AssetCentre servers and agents, enabling attackers to compromise engineering workstations and PLCs across OT networks; Rockwell released fixes and recommends upgrading to v11 and applying secure configurations (SSL/IPSec) as mitigations.

Your team is not currently subscribed to this feed. You must subscribe to it in order to see this post.