Vulnerability index

Browse CVEs

79 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

Deltav Workstation MEDIUM 5.5
CVE-2021-26264

A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service cond…

No fix yet
Fix from $1,600 2022-01-28
Xweb300d Evo Firmware CRITICAL 9.8
CVE-2021-45427EPSS 19%

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete …

No fix yet
Fix from $2,300 2021-12-30
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-38485

The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to re…

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42538

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42539

The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved …

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42540

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwri…

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Wireless 1410 Gateway Firmware HIGH 8.8
CVE-2021-42542

The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.

Fix: 4.7.94+
Fix from $1,950 2021-10-22
Wireless 1410 Gateway Firmware MEDIUM 6.5
CVE-2021-42536

The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

Fix: 4.7.94+
Fix from $1,600 2021-10-22
Wireless 1410 Gateway Firmware CRITICAL 10.0
CVE-2020-12030

There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN se…

Fix: after 4.7.84
Fix from $2,300 2021-09-29
Proficy Machine Edition MEDIUM 5.3
CVE-2021-29297

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via craft…

Mitigation only
Fix from $1,600 2021-07-30
Proficy Machine Edition MEDIUM 5.3
CVE-2021-29298

Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash…

Mitigation only
Fix from $1,600 2021-07-30
X Stream Enhanced Xegp Firmware CRITICAL 9.8
CVE-2021-27459

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvali…

Mitigation only
Fix from $2,300 2021-05-20
X Stream Enhanced Xegp Firmware HIGH 7.5
CVE-2021-27457

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algo…

Mitigation only
Fix from $1,950 2021-05-20
X Stream Enhanced Xegp Firmware HIGH 7.5
CVE-2021-27461

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to …

Mitigation only
Fix from $1,950 2021-05-20
X Stream Enhanced Xegp Firmware MEDIUM 6.1
CVE-2021-27465

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage in…

Mitigation only
Fix from $1,600 2021-05-20
X Stream Enhanced Xegp Firmware MEDIUM 6.1
CVE-2021-27467

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attac…

Mitigation only
Fix from $1,600 2021-05-20
X Stream Enhanced Xegp Firmware MEDIUM 5.3
CVE-2021-27463

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies…

Mitigation only
Fix from $1,600 2021-05-20
Wireless 1420 Gateway Firmware HIGH 8.8
CVE-2020-19417

Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sendi…

No fix yet
Fix from $1,950 2021-03-10
Smart Wireless Gateway 1420 Firmware HIGH 7.5
CVE-2020-19419

Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the admini…

No fix yet
Fix from $1,950 2021-03-10
Rosemount Transmitter Interface Software HIGH 7.8
CVE-2020-12525

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data …

Fix: 3.5 / 4.5+
Fix from $1,950 2021-01-22
X Stream Enhanced Xegp Firmware HIGH 7.5
CVE-2020-27254

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper aut…

Mitigation only
Fix from $1,950 2020-12-21
Valvelink HIGH 7.8
CVE-2020-6971

In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate p…

Fix: after 13.4.118
Fix from $1,950 2020-03-05
Openenterprise Scada Server CRITICAL 9.8
CVE-2020-6970

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) a…

Fix: after 3.3.3
Fix from $2,300 2020-02-19
Rx3i Cpe100 Firmware HIGH 7.5
CVE-2019-13524

GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) …

Patch available
Fix from $1,950 2020-01-16
Ovation Ocr400 Firmware HIGH 8.8
CVE-2019-10965

In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves im…

Fix: after 3.3.1
Fix from $1,950 2019-05-28
Ovation Ocr400 Firmware HIGH 8.8
CVE-2019-10967

In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves i…

Fix: after 3.3.1
Fix from $1,950 2019-05-28
Liebert Challenger Firmware MEDIUM 6.1
CVE-2019-12167

httpGetSet/httpGet.htm on Emerson Network Power Liebert Challenger 5.1E0.5 devices allows XSS via the statusstr parameter.

Mitigation only
Fix from $1,600 2019-05-22
Ve6046 Firmware CRITICAL 9.8
CVE-2018-11691

Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ mana…

Mitigation only
Fix from $2,300 2019-05-14
Deltav MEDIUM 6.5
CVE-2018-19021

A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3,…

Mitigation only
Fix from $1,600 2019-01-25
Ams Device Manager CRITICAL 9.8
CVE-2018-14804

Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

Fix: after 13.5
Fix from $2,300 2018-10-01