Show filters
41 Total Results
Displaying 1-10 of 41
Sort by:
Attacker Value
Unknown

CVE-2022-46732

Disclosure Date: January 18, 2023 (last updated October 08, 2023)
Even if the authentication fails for local service authentication, the requested command could still execute regardless of authentication status.
Attacker Value
Unknown

CVE-2022-46660

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
An unauthorized user could alter or write files with full control over the path and content of the file.
Attacker Value
Unknown

CVE-2022-46331

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
An unauthorized user could possibly delete any file on the system.
Attacker Value
Unknown

CVE-2022-43494

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
An unauthorized user could be able to read any file on the system, potentially exposing sensitive information.
Attacker Value
Unknown

CVE-2022-38469

Disclosure Date: January 18, 2023 (last updated November 08, 2023)
An unauthorized user with network access and the decryption key could decrypt sensitive data, such as usernames and passwords.
Attacker Value
Unknown

CVE-2022-2791

Disclosure Date: November 22, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.
Attacker Value
Unknown

CVE-2022-2793

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.
Attacker Value
Unknown

CVE-2022-2792

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
Attacker Value
Unknown

CVE-2022-2790

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).
Attacker Value
Unknown

CVE-2022-2789

Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.