Emerson
emerson
85 CVEs • 151 products
Products (151)
Click to collapseToggle
Products (151)
Click to collapse
CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Emerson 8Data Record Ad FlexloggerG Web Development Software+5 moreJun 17, 2026 Feb 20, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges. |
1Emerson 8Data Record Ad FlexloggerG Web Development Software+5 moreJun 17, 2026 Feb 20, 2024 N/A· v4 7.8 HIGH· v3 N/A· v2 Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.
|
1Emerson 3Gc1500xa Firmware Gc370xa FirmwareGc700xa FirmwareJun 17, 2026 Feb 9, 2024 N/A· v4 8.1 HIGH· v3 N/A· v2 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities. |
1Emerson 3Gc1500xa Firmware Gc370xa FirmwareGc700xa FirmwareJun 17, 2026 Feb 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
|
1Emerson 3Gc1500xa Firmware Gc370xa FirmwareGc700xa FirmwareJun 17, 2026 Feb 9, 2024 N/A· v4 9.8 CRITICAL· v3 N/A· v2
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.
|
1Emerson 3Gc1500xa Firmware Gc370xa FirmwareGc700xa FirmwareJun 17, 2026 Feb 9, 2024 N/A· v4 9.1 CRITICAL· v3 N/A· v2 In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition. |
1Emerson 5Dl8000 Firmware Roc809 FirmwareRoc809l Firmware+2 moreJun 17, 2026 Aug 2, 2023 N/A· v4 9.4 CRITICAL· v3 N/A· v2 ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition. |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Dec 26, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-seri...Show more |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC. |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection f...Show more |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists. |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (B...Show more |
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic. |
Emerson Electric's Proficy Machine Edition Version 9.80 and prior is vulnerable to CWE-29 Path Traversal: '\..\Filename', also known as a ZipSlip attack, through an upload procedure which enables attackers to implant a m...Show more |
1Emerson 2Controlwave Micro Firmware Controlwave Pac FirmwareJun 17, 2026 Aug 17, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containin...Show more |
1Emerson 5Dl8000 Firmware Fb3000 Rtu FirmwareRoc800l Firmware+2 moreJun 17, 2026 Aug 16, 2022 N/A· v4 9.8 CRITICAL· v3 N/A· v2 The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 20...Show more |
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user...Show more |
1Emerson 25Deltav Distributed Control System Deltav Distributed Control System Sq Controller FirmwareDeltav Distributed Control System Sx Controller Firmware+22 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSL...Show more |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is di...Show more |
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-s...Show more |