Vulnerability index

Browse CVEs

79 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Data Record Ad HIGH 7.8
CVE-2024-1155

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Data Record Ad HIGH 7.8
CVE-2024-1156

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an…

Fix: 2024_q1+
Fix from $1,950 2024-02-20
Gc370xa Firmware CRITICAL 9.8
CVE-2023-49716

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote co…

Mitigation only
Fix from $2,300 2024-02-09
Gc370xa Firmware HIGH 8.1
CVE-2023-51761

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm…

Mitigation only
Fix from $1,950 2024-02-09
Gc370xa Firmware CRITICAL 9.8
CVE-2023-46687

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root co…

Mitigation only
Fix from $2,300 2024-02-09
Gc370xa Firmware CRITICAL 9.1
CVE-2023-43609

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive informatio…

Mitigation only
Fix from $2,300 2024-02-09
Roc809 Firmware CRITICAL 9.4
CVE-2023-1935

ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of…

Mitigation only
Fix from $2,300 2023-08-02
Deltav Distributed Control System Sq Controller Firmware HIGH 7.8
CVE-2022-30260

Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signatur…

Fix: 14.3+
Fix from $1,950 2022-12-26
Proficy HIGH 7.8
CVE-2022-2791

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will …

Fix: after 9.00
Fix from $1,950 2022-11-22
Electric\'s Proficy HIGH 7.8
CVE-2022-2793

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentica…

Fix: after 9.0.0
Fix from $1,950 2022-08-19
Electric\'s Proficy HIGH 7.5
CVE-2022-2792

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a dire…

Fix: after 9.0.0
Fix from $1,950 2022-08-19
Electric\'s Proficy MEDIUM 5.9
CVE-2022-2790

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does…

Fix: after 9.0.0
Fix from $1,600 2022-08-19
Electric\'s Proficy MEDIUM 5.5
CVE-2022-2789

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can di…

Fix: after 9.0.0
Fix from $1,600 2022-08-19
Electric\'s Proficy HIGH 7.3
CVE-2022-2788

Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip att…

Fix: after 9.80
Fix from $1,950 2022-08-19
Controlwave Pac Firmware HIGH 7.8
CVE-2022-30262

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmwar…

Fix: after 2022-05-02
Fix from $1,950 2022-08-17
Dl8000 Firmware CRITICAL 9.8
CVE-2022-30264

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 500…

Fix: 2022-05-02+
Fix from $2,300 2022-08-16
Openbsi MEDIUM 5.5
CVE-2022-29959

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT…

Fix: 5.9+
Fix from $1,600 2022-08-16
Openbsi MEDIUM 5.5
CVE-2022-29960

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES…

Fix: 5.9+
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29962

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but …

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29963

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces…

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System Sq Controller Firmware MEDIUM 5.5
CVE-2022-29964

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell…

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System MEDIUM 5.5
CVE-2022-29965

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on …

Fix: after 2022-04-29
Fix from $1,600 2022-07-26
Deltav Distributed Control System HIGH 7.8
CVE-2022-29957

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid…

Fix: after 2022-04-29
Fix from $1,950 2022-07-26
Openenterprise Scada Server MEDIUM 6.5
CVE-2020-16235

Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external system…

Fix: after 3.3.5
Fix from $1,600 2022-05-19
Openenterprise Scada Server CRITICAL 9.8
CVE-2020-10640

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execut…

Fix: after 3.3.4
Fix from $2,300 2022-02-24
Openenterprise Scada Server HIGH 7.5
CVE-2020-10636

Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.

Fix: after 3.3.4
Fix from $1,950 2022-02-24
Openenterprise Scada Server MEDIUM 5.3
CVE-2020-10632

Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, whic…

Fix: after 3.3.4
Fix from $1,600 2022-02-24
Dixell Xweb 500 Firmware CRITICAL 9.8
CVE-2021-45420EPSS 18%

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg…

Mitigation only
Fix from $2,300 2022-02-14
Dixell Xweb 500 Firmware HIGH 7.5
CVE-2021-45421

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to …

No fix yet
Fix from $1,950 2022-02-14
Deltav HIGH 7.3
CVE-2021-44463

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Contr…

Mitigation only
Fix from $1,950 2022-01-28