Show filters
85 Total Results
Displaying 1-10 of 85
Sort by:
Attacker Value
Unknown
CVE-2024-1156
Disclosure Date: February 20, 2024 (last updated February 13, 2025)
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
0
Attacker Value
Unknown
CVE-2024-1155
Disclosure Date: February 20, 2024 (last updated February 13, 2025)
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
0
Attacker Value
Unknown
CVE-2023-51761
Disclosure Date: February 09, 2024 (last updated February 15, 2024)
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.
0
Attacker Value
Unknown
CVE-2023-49716
Disclosure Date: February 09, 2024 (last updated February 15, 2024)
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
0
Attacker Value
Unknown
CVE-2023-46687
Disclosure Date: February 09, 2024 (last updated February 15, 2024)
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.
0
Attacker Value
Unknown
CVE-2023-43609
Disclosure Date: February 09, 2024 (last updated February 16, 2024)
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2023-1935
Disclosure Date: August 02, 2023 (last updated October 08, 2023)
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.
0
Attacker Value
Unknown
CVE-2022-30260
Disclosure Date: December 26, 2022 (last updated October 08, 2023)
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
0
Attacker Value
Unknown
CVE-2022-2791
Disclosure Date: November 22, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.
0
Attacker Value
Unknown
CVE-2022-2793
Disclosure Date: August 19, 2022 (last updated October 08, 2023)
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.
0