Vulnerability index

Browse CVEs

79 matching
Filters 1 Clear all
Severity

Filters apply as you choose them.

HIGH 7.8 CVE-2024-1155 Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enab… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 HIGH 7.8 CVE-2024-1156 Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information an… Data Record Ad 2024_q1+ Fix from $1,9502024-02-20 CRITICAL 9.8 CVE-2023-49716 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote co… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 HIGH 8.1 CVE-2023-51761 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire adm… Gc370xa Firmware Mitigation only Fix from $1,9502024-02-09 CRITICAL 9.8 CVE-2023-46687 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root co… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 CRITICAL 9.1 CVE-2023-43609 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive informatio… Gc370xa Firmware Mitigation only Fix from $2,3002024-02-09 CRITICAL 9.4 CVE-2023-1935 ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of… Roc809 Firmware Mitigation only Fix from $2,3002023-08-02 HIGH 7.8 CVE-2022-30260 Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signatur… Deltav Distributed Control System Sq Controller Firmware 14.3+ Fix from $1,9502022-12-26 HIGH 7.8 CVE-2022-2791 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will … Proficy after 9.00 Fix from $1,9502022-11-22 HIGH 7.8 CVE-2022-2793 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentica… Electric\'s Proficy after 9.0.0 Fix from $1,9502022-08-19 HIGH 7.5 CVE-2022-2792 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a dire… Electric\'s Proficy after 9.0.0 Fix from $1,9502022-08-19 MEDIUM 5.9 CVE-2022-2790 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does… Electric\'s Proficy after 9.0.0 Fix from $1,6002022-08-19 MEDIUM 5.5 CVE-2022-2789 Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can di… Electric\'s Proficy after 9.0.0 Fix from $1,6002022-08-19 HIGH 7.3 CVE-2022-2788 Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip att… Electric\'s Proficy after 9.80 Fix from $1,9502022-08-19 HIGH 7.8 CVE-2022-30262 The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmwar… Controlwave Pac Firmware after 2022-05-02 Fix from $1,9502022-08-17 CRITICAL 9.8 CVE-2022-30264 The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 500… Dl8000 Firmware 2022-05-02+ Fix from $2,3002022-08-16 MEDIUM 5.5 CVE-2022-29959 Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RT… Openbsi 5.9+ Fix from $1,6002022-08-16 MEDIUM 5.5 CVE-2022-29960 Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES… Openbsi 5.9+ Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29962 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but … Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29963 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides acces… Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29964 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell… Deltav Distributed Control System Sq Controller Firmware after 2022-04-29 Fix from $1,6002022-07-26 MEDIUM 5.5 CVE-2022-29965 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on … Deltav Distributed Control System after 2022-04-29 Fix from $1,6002022-07-26 HIGH 7.8 CVE-2022-29957 The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wid… Deltav Distributed Control System after 2022-04-29 Fix from $1,9502022-07-26 MEDIUM 6.5 CVE-2020-16235 Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external system… Openenterprise Scada Server after 3.3.5 Fix from $1,6002022-05-19 CRITICAL 9.8 CVE-2020-10640 Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execut… Openenterprise Scada Server after 3.3.4 Fix from $2,3002022-02-24 HIGH 7.5 CVE-2020-10636 Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained. Openenterprise Scada Server after 3.3.4 Fix from $1,9502022-02-24 MEDIUM 5.3 CVE-2020-10632 Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, whic… Openenterprise Scada Server after 3.3.4 Fix from $1,6002022-02-24 CRITICAL 9.8 CVE-2021-45420EPSS 18% Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cg… Dixell Xweb 500 Firmware Mitigation only Fix from $2,3002022-02-14 HIGH 7.5 CVE-2021-45421 Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to … Dixell Xweb 500 Firmware No fix yet Fix from $1,9502022-02-14 HIGH 7.3 CVE-2021-44463 Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Contr… Deltav Mitigation only Fix from $1,9502022-01-28