Show filters
85 Total Results
Displaying 21-30 of 85
Sort by:
Attacker Value
Unknown

CVE-2022-29962

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
Attacker Value
Unknown

CVE-2022-29960

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.
Attacker Value
Unknown

CVE-2022-29957

Disclosure Date: July 26, 2022 (last updated October 07, 2023)
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.
Attacker Value
Unknown

CVE-2020-16235

Disclosure Date: May 19, 2022 (last updated October 07, 2023)
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.
Attacker Value
Unknown

CVE-2020-10640

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.
Attacker Value
Unknown

CVE-2020-10636

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.
Attacker Value
Unknown

CVE-2020-10632

Disclosure Date: February 24, 2022 (last updated October 07, 2023)
Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.
Attacker Value
Unknown

CVE-2021-45421

Disclosure Date: February 14, 2022 (last updated November 08, 2023)
Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced
Attacker Value
Unknown

CVE-2021-45420

Disclosure Date: February 14, 2022 (last updated November 08, 2023)
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced
Attacker Value
Unknown

CVE-2021-45427

Disclosure Date: December 30, 2021 (last updated February 23, 2025)
Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.