Emerson
emerson
85 CVEs • 151 products
Products (151)
Click to collapseToggle
Products (151)
Click to collapse
CVEs (85)
CVE VENDORS PRODUCTS UPDATED PUBLISHED CVSS |
|---|
1Emerson 24Deltav Distributed Control System Sq Controller Firmware Deltav Distributed Control System Sx Controller FirmwareSe4002s1t2b6 High Side 40 Pin Mass I/o Terminal Block Firmware+21 moreJun 17, 2026 Jul 26, 2022 N/A· v4 5.5 MEDIUM· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series,...Show more |
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain sy...Show more |
1Emerson 1Deltav Distributed Control System Jun 17, 2026 Jul 26, 2022 N/A· v4 7.8 HIGH· v3 N/A· v2 The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (1...Show more |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 May 19, 2022 N/A· v4 6.5 MEDIUM· v3 2.1 LOW· v2 Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained. |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 Feb 24, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service. |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 Feb 24, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained. |
1Emerson 1Openenterprise Scada Server Jun 17, 2026 Feb 24, 2022 N/A· v4 5.3 MEDIUM· v3 5.0 MEDIUM· v2 Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner. |
1Emerson 1Dixell Xweb 500 Firmware Jul 9, 2026 Feb 14, 2022 N/A· v4 7.5 HIGH· v3 5.0 MEDIUM· v2 Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has n...Show more |
1Emerson 1Dixell Xweb 500 Firmware Jul 9, 2026 Feb 14, 2022 N/A· v4 9.8 CRITICAL· v3 10.0 HIGH· v2 Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the t...Show more |
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are st...Show more |
1Emerson 2Deltav Distributed Control System Deltav WorkstationJun 17, 2026 Jan 28, 2022 N/A· v4 5.5 MEDIUM· v3 4.9 MEDIUM· v2 A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition. |
1Emerson 1Xweb300d Evo Firmware Jun 17, 2026 Dec 30, 2021 N/A· v4 9.8 CRITICAL· v3 7.5 HIGH· v2 Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and di...Show more |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 6.5 MEDIUM· v3 4.0 MEDIUM· v2 The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1410d Gateway FirmwareWireless 1420 Gateway FirmwareJun 17, 2026 Oct 22, 2021 N/A· v4 8.8 HIGH· v3 6.5 MEDIUM· v2 The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk. |
1Emerson 3Wireless 1410 Gateway Firmware Wireless 1420 Gateway FirmwareWireless 1552wu Gateway FirmwareJun 17, 2026 Sep 29, 2021 N/A· v4 10.0 CRITICAL· v3 6.8 MEDIUM· v2 There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in expo...Show more |
1Emerson 1Proficy Machine Edition Jun 17, 2026 Jul 30, 2021 N/A· v4 5.3 MEDIUM· v3 2.6 LOW· v2 Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the comp...Show more |