CVE-2021-27471
Rockwell Automation Connected Components Workbench vulnerability analysis and mitigation

Overview

The vulnerability (CVE-2021-27471) affects Rockwell Automation Connected Components Workbench v12.00.00 and prior versions. It is a path traversal vulnerability (CWE-22) where the parsing mechanism that processes certain file types does not provide input sanitization for file paths (CISA Advisory).

Technical details

The vulnerability has been assigned a CVSS v3.1 base score of 7.7 HIGH with vector string (AV:L/AC:H/PR:N/UI:R/S:C/C:H/I:H/A:H). The vulnerability allows an attacker to craft malicious files that, when opened by Connected Components Workbench, can traverse the file system. The exploitation requires user interaction to be successful (CISA Advisory, NVD).

Impact

If successfully exploited, an attacker could overwrite existing files and create additional files with the same permissions of the Connected Components Workbench software. The vulnerability affects multiple critical infrastructure sectors including Commercial Facilities, Defense Industrial Base, Energy, and Government Facilities globally (CISA Advisory).

Mitigation and workarounds

Rockwell Automation recommends users update to Connected Components Workbench v13.00.00 or later. If upgrade is not possible, users should: run Connected Components Workbench as a User (not Administrator), avoid opening untrusted files, employ training programs for phishing awareness, use Microsoft AppLocker, and follow the least-privilege principle (CISA Advisory).

Additional resources


SourceThis report was generated using AI

Related Rockwell Automation Connected Components Workbench vulnerabilities:

CVE ID

Severity

Score

Technologies

Component name

CISA KEV exploit

Has fix

Published date

CVE-2021-27475HIGH8.6
  • Rockwell Automation Connected Components WorkbenchRockwell Automation Connected Components Workbench
  • cpe:2.3:a:rockwellautomation:connected_components_workbench
NoNoMar 23, 2022
CVE-2021-27471HIGH8.6
  • Rockwell Automation Connected Components WorkbenchRockwell Automation Connected Components Workbench
  • cpe:2.3:a:rockwellautomation:connected_components_workbench
NoNoMar 23, 2022
CVE-2021-27473HIGH8.2
  • Rockwell Automation Connected Components WorkbenchRockwell Automation Connected Components Workbench
  • cpe:2.3:a:rockwellautomation:connected_components_workbench
NoNoMar 23, 2022
CVE-2014-5424HIGH7.5
  • Rockwell Automation Connected Components WorkbenchRockwell Automation Connected Components Workbench
  • cpe:2.3:a:rockwellautomation:connected_components_workbench
NoNoNov 14, 2014
CVE-2022-1018MEDIUM5.5
  • Rockwell Automation Connected Components WorkbenchRockwell Automation Connected Components Workbench
  • cpe:2.3:a:rockwellautomation:connected_components_workbench
NoNoApr 01, 2022

Free Vulnerability Assessment

Benchmark your Cloud Security Posture

Evaluate your cloud security practices across 9 security domains to benchmark your risk level and identify gaps in your defenses.

Request assessment

Get a personalized demo

Ready to see Wiz in action?

"Best User Experience I have ever seen, provides full visibility to cloud workloads."
David EstlickCISO
"Wiz provides a single pane of glass to see what is going on in our cloud environments."
Adam FletcherChief Security Officer
"We know that if Wiz identifies something as critical, it actually is."
Greg PoniatowskiHead of Threat and Vulnerability Management