ZeroHour

Vulnerabilities

69 CVEs · NVD, GitHub Advisories, CISA KEV, FIRST EPSS, GitHub PoC repos

CVEVulnerabilityCVSSEPSSFlagsAffectedExposurePublished
CVE-2024-1156
+1 in the same advisory: …1155
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potential

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

NVD description · AI analysis pending
7.8<1% PoC
  • emerson data record ad
  • emerson flexlogger
  • emerson g web development software
  • +1 more
CVE-2023-46687
+3 in the same advisory: …49716 …43609 …51761
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

NVD description · AI analysis pending
9.8
group max
<1%
  • emerson gc370xa firmware
  • emerson gc700xa firmware
  • emerson gc1500xa firmware
CVE-2023-1935
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device

ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.

NVD description · AI analysis pending
9.4<1%
  • emerson roc809 firmware
  • emerson roc827 firmware
  • emerson roc809l firmware
  • +1 more
CVE-2022-30260
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature).

Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.

NVD description · AI analysis pending
7.8<1%
  • emerson deltav distributed control system sq controller firmware
  • emerson deltav distributed control system sx controller firmware
  • emerson se4002s1t2b6 high side 40-pin mass i\/o terminal block firmware
  • +1 more
CVE-2022-2791
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.

NVD description · AI analysis pending
7.8<1%
  • emerson proficy
CVE-2022-2793
+4 in the same advisory: …2792 …2788 …2790 …2789
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or aut

Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.

NVD description · AI analysis pending
7.8
group max
<1%
  • emerson electric\'s proficy
CVE-2022-30262
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity.

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

NVD description · AI analysis pending
7.8<1%
  • emerson controlwave pac firmware
  • emerson controlwave micro firmware
CVE-2022-30264
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations.

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

NVD description · AI analysis pending
9.8<1%
  • emerson dl8000 firmware
  • emerson roc809 firmware
  • emerson roc800l firmware
  • +1 more
CVE-2022-29959
Emerson OpenBSI through 2022-04-29 mishandles credential storage.

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

NVD description · AI analysis pending
5.5<1%
  • emerson openbsi
CVE-2022-29957
+1 in the same advisory: …29965
The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication.

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

NVD description · AI analysis pending
7.8
group max
<1%
  • emerson deltav distributed control system
CVE-2022-29964
+2 in the same advisory: …29963 …29962
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords.

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

NVD description · AI analysis pending
5.5<1%
  • emerson deltav distributed control system sq controller firmware
  • emerson deltav distributed control system sx controller firmware
  • emerson se4002s1t2b6 high side 40-pin mass i\/o terminal block firmware
  • +1 more
CVE-2022-29960
Emerson OpenBSI through 2022-04-29 uses weak cryptography.

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

NVD description · AI analysis pending
5.5<1%
  • emerson openbsi
CVE-2020-16235
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obt

Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.

NVD description · AI analysis pending
6.5<1%
  • emerson openenterprise scada server
CVE-2020-10640
+2 in the same advisory: …10636 …10632
Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a s

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

NVD description · AI analysis pending
9.8
group max
3%
  • emerson openenterprise scada server
CVE-2021-45420
+1 in the same advisory: …45421
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_ut

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.

NVD description · AI analysis pending
9.8
group max
18% PoC
  • emerson dixell xweb-500 firmware
CVE-2021-44463
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

NVD description · AI analysis pending
7.3<1%
  • emerson deltav
CVE-2021-26264
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

NVD description · AI analysis pending
5.5<1%
  • emerson deltav workstation
  • emerson deltav distributed control system
CVE-2021-45427
Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by:

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

NVD description · AI analysis pending
9.819% PoC
  • emerson xweb300d evo firmware
CVE-2021-42542
The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.

The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.

NVD description · AI analysis pending
8.8
group max
1%
  • emerson wireless 1410 gateway firmware
  • emerson wireless 1410d gateway firmware
  • emerson wireless 1420 gateway firmware
CVE-2020-12030
There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled.

There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

NVD description · AI analysis pending
10.01%
  • emerson wireless 1410 gateway firmware
  • emerson wireless 1420 gateway firmware
  • emerson wireless 1552wu gateway firmware
CVE-2021-29297
+1 in the same advisory: …29298
Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

NVD description · AI analysis pending
5.3<1%
  • emerson proficy machine edition
CVE-2021-27459
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer.

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

NVD description · AI analysis pending
9.8
group max
2%
  • emerson x-stream enhanced xegp firmware
  • emerson x-stream enhanced xegk firmware
  • emerson x-stream enhanced xefd firmware
  • +1 more
CVE-2020-19419
Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator con

Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

NVD description · AI analysis pending
7.53% PoC
  • emerson smart wireless gateway 1420 firmware
CVE-2020-19417
Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending speciall

Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application.

NVD description · AI analysis pending
8.83% PoC
  • emerson wireless 1420 gateway firmware
CVE-2020-12525
M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its proj

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

NVD description · AI analysis pending
7.81%
  • emerson rosemount transmitter interface software
  • emerson pactware
  • emerson dtminspector 3
  • +1 more