AID
Automation
Information Directory
HomeCVE FeedBrands
AID
Automation Information Directory
CVE data sourced from NIST NVD · Documentation links from official sources
Home›Brands›Emerson Electric
EM
Platform

Emerson Electric

DeltaV DCS, Ovation process control, Fisher instrumentation, and AMS Device Manager for process automation.

https://www.emerson.com/en-us/automation →
6
Total CVEs
0
Resources
0
CRIT
0
HIGH
5
MED
1
LOW
CVEsCVEsSpecsTech SpecsDocsTech DocsImplImplementationsExamplesExamples
5 / 6
CVE-2022-2792MEDIUM

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.

Aug 19, 2022
6.6
CVE-2022-2791MEDIUM

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.

Nov 22, 2022
5.9
CVE-2022-2793MEDIUM

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.

Aug 19, 2022
5.9
CVE-2022-2790MEDIUM

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).

Aug 19, 2022
5.9
CVE-2022-2789MEDIUM

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.

Aug 19, 2022
4.7
CVE ID ⇅Severity ↓CVSS ⇅DescriptionPublished ⇅
CVE-2022-2792MEDIUM
6.6
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper …Aug 19, 2022›
CVE-2022-2791MEDIUM
5.9
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestric…Nov 22, 2022›
CVE-2022-2793MEDIUM
5.9
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing S…Aug 19, 2022›
CVE-2022-2790MEDIUM
5.9
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper …Aug 19, 2022›
CVE-2022-2789MEDIUM
4.7
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insuffici…Aug 19, 2022›