Rockwell Automation FactoryTalk AssetCentre
FactoryTalk AssetCentre versions 10.00 and earlier contain multiple vulnerabilities (CWE-502 insecure deserialization, CWE-676 unsafe function use, CWE-78 OS command injection, CWE-89 SQL injection) that allow unauthenticated remote attackers to execute arbitrary commands, inject SQL, or achieve remote code execution. These vulnerabilities affect asset management and control system integration across manufacturing and utility operations. Rockwell Automation recommends upgrading to version 11 or later. Organizations unable to upgrade should implement IPsec and use built-in security features per QA46277.
- Network access to FactoryTalk AssetCentre service port (default 443)
- No valid credentials required
Patching may require device reboot — plan for process interruption
/api/v1/advisories/675d65a2-4190-44f2-be25-a5cf8aa619e7Get OT security insights every Tuesday
Advisory breakdowns, a weekly summary, and incident analyses for the people actually defending OT environments. Free, no account required.