← Back

Emerson

emerson

85 CVEs • 151 products

Products (151)

Click to collapse
Toggle
Deltav
deltav
Openbsi
openbsi
Flexlogger
flexlogger
Labview Nxg
labview_nxg
Valvelink
valvelink
Proficy
proficy
Ve6046
ve6046
Rx3i Cpe100
rx3i_cpe100
Rx3i Cpe115
rx3i_cpe115
Rx3i Cpe302
rx3i_cpe302

CVEs (85)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emerson
8Data Record Ad
FlexloggerG Web Development Software+5 more
Jun 17, 2026
Feb 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.
1Emerson
8Data Record Ad
FlexloggerG Web Development Software+5 more
Jun 17, 2026
Feb 20, 2024
N/A· v4
7.8 HIGH· v3
N/A· v2
Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
1Emerson
3Gc1500xa Firmware
Gc370xa FirmwareGc700xa Firmware
Jun 17, 2026
Feb 9, 2024
N/A· v4
8.1 HIGH· v3
N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.
1Emerson
3Gc1500xa Firmware
Gc370xa FirmwareGc700xa Firmware
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
1Emerson
3Gc1500xa Firmware
Gc370xa FirmwareGc700xa Firmware
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.8 CRITICAL· v3
N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.
1Emerson
3Gc1500xa Firmware
Gc370xa FirmwareGc700xa Firmware
Jun 17, 2026
Feb 9, 2024
N/A· v4
9.1 CRITICAL· v3
N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.
1Emerson
5Dl8000 Firmware
Roc809 FirmwareRoc809l Firmware+2 more
Jun 17, 2026
Aug 2, 2023
N/A· v4
9.4 CRITICAL· v3
N/A· v2
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Dec 26, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-seri...Show more
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.Show less
1Emerson
1Proficy
Jun 17, 2026
Nov 22, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection f...Show more
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.Show less
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
7.5 HIGH· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
5.9 MEDIUM· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (B...Show more
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).Show less
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
1Emerson
1Electric's Proficy
Jun 17, 2026
Aug 19, 2022
N/A· v4
7.3 HIGH· v3
N/A· v2
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a m...Show more
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a malicious .BLZ file on the PLC. The file can transfer through the engineering station onto Windows in a way that executes the malicious code.Show less
1Emerson
2Controlwave Micro Firmware
Controlwave Pac Firmware
Jun 17, 2026
Aug 17, 2022
N/A· v4
7.8 HIGH· v3
N/A· v2
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containin...Show more
The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.Show less
1Emerson
5Dl8000 Firmware
Fb3000 Rtu FirmwareRoc800l Firmware+2 more
Jun 17, 2026
Aug 16, 2022
N/A· v4
9.8 CRITICAL· v3
N/A· v2
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 20...Show more
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.Show less
1Emerson
1Openbsi
Jun 17, 2026
Aug 16, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user...Show more
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.Show less
1Emerson
25Deltav Distributed Control System
Deltav Distributed Control System Sq Controller FirmwareDeltav Distributed Control System Sx Controller Firmware+22 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSL...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.Show less
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is di...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.Show less
1Emerson
24Deltav Distributed Control System Sq Controller Firmware
Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 more
Jun 17, 2026
Jul 26, 2022
N/A· v4
5.5 MEDIUM· v3
N/A· v2
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-s...Show more
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.Show less