← Back

Emerson

emerson

85 CVEs • 151 products

Products (151)

Click to collapse
Toggle
Deltav
deltav
Openbsi
openbsi
Flexlogger
flexlogger
Labview Nxg
labview_nxg
Valvelink
valvelink
Proficy
proficy
Ve6046
ve6046
Rx3i Cpe100
rx3i_cpe100
Rx3i Cpe115
rx3i_cpe115
Rx3i Cpe302
rx3i_cpe302

CVEs (85)

CVE
VENDORS
PRODUCTS
UPDATED
PUBLISHED
CVSS
1Emerson
1Ams Device Manager
Nov 21, 2024
Oct 1, 2018
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
1Emerson
1Deltav
Nov 21, 2024
Aug 23, 2018
N/A· v4
7.8 HIGH· v3
6.8 MEDIUM· v2
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.
1Emerson
1Deltav
Nov 21, 2024
Aug 23, 2018
N/A· v4
7.8 HIGH· v3
4.6 MEDIUM· v2
Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affected products.
1Emerson
1Deltav
Nov 21, 2024
Aug 21, 2018
N/A· v4
8.8 HIGH· v3
6.5 MEDIUM· v2
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.
1Emerson
1Deltav
Nov 21, 2024
Aug 21, 2018
N/A· v4
8.8 HIGH· v3
5.8 MEDIUM· v2
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to allow arbitrary code execution.
1Emerson
1Controlwave Micro Firmware
Jun 17, 2026
Mar 7, 2018
N/A· v4
7.5 HIGH· v3
5.0 MEDIUM· v2
A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based...Show more
A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based buffer overflow vulnerability caused by sending crafted packets on Port 20547 could force the PLC to change its state into halt mode.Show less
1Emerson
2Se4801t0x Redundant Wireless I/o Card Firmware
Se4801t1x Simplex Wireless I/o Card Firmware
May 13, 2026
Feb 13, 2017
N/A· v4
5.0 MEDIUM· v3
5.4 MEDIUM· v2
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release...Show more
An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell) functionality enabled unnecessarily.Show less
1Emerson
1Deltav
May 13, 2026
Feb 13, 2017
N/A· v4
6.8 MEDIUM· v3
4.9 MEDIUM· v2
An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control syste...Show more
An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control system.Show less
1Emerson
1Liebert Sitescan Web
May 13, 2026
Feb 13, 2017
N/A· v4
9.8 CRITICAL· v3
7.5 HIGH· v2
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the appli...Show more
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.Show less
1Emerson
1Ams Device Manager
May 6, 2026
May 26, 2015
N/A· v4
N/A· v3
6.5 MEDIUM· v2
SQL injection vulnerability in Emerson AMS Device Manager before 13 allows remote authenticated users to gain privileges via malformed input.
1Emerson
6Dl 8000 Remote Terminal Unit
Dl 8000 Remote Terminal Unit FirmwareRoc 800 Remote Terminal Unit+3 more
May 6, 2026
Dec 8, 2014
N/A· v4
N/A· v3
10.0 HIGH· v2
Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a...Show more
Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack.Show less
1Emerson
1Deltav
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
7.5 HIGH· v2
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.Show less
1Emerson
1Deltav
May 6, 2026
May 22, 2014
N/A· v4
N/A· v3
4.6 MEDIUM· v2
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that...Show more
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.Show less
1Emerson
1Network Power Avocent Mergepoint Unity 2016 Firmware
Apr 29, 2026
Jan 24, 2014
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as de...Show more
Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file.Show less
2Emerson
Enea
4Dl 8000 Remote Terminal Unit
OseRoc 800 Remote Terminal Unit+1 more
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
9.0 HIGH· v2
The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easi...Show more
The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the ROM contents from a product installation elsewhere.Show less
2Emerson
Enea
4Dl 8000 Remote Terminal Unit
OseRoc 800 Remote Terminal Unit+1 more
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadc...Show more
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.Show less
2Emerson
Enea
4Dl 8000 Remote Terminal Unit
OseRoc 800 Remote Terminal Unit+1 more
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to exe...Show more
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.Show less
2Emerson
Enea
4Dl 8000 Remote Terminal Unit
OseRoc 800 Remote Terminal Unit+1 more
Apr 29, 2026
Oct 3, 2013
N/A· v4
N/A· v3
10.0 HIGH· v2
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload fil...Show more
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.Show less
1Emerson
3Deltav Se3006 Sd Plus Controller
Deltav Ve3005 Controller MdDeltav Ve3006 Controller Md Plus
Apr 29, 2026
Mar 11, 2013
N/A· v4
N/A· v3
6.1 MEDIUM· v2
The Emerson DeltaV SE3006 through 11.3.1, DeltaV VE3005 through 10.3.1 and 11.x through 11.3.1, and DeltaV VE3006 through 10.3.1 and 11.x through 11.3.1 allow remote attackers to cause a denial of service (device restart...Show more
The Emerson DeltaV SE3006 through 11.3.1, DeltaV VE3005 through 10.3.1 and 11.x through 11.3.1, and DeltaV VE3006 through 10.3.1 and 11.x through 11.3.1 allow remote attackers to cause a denial of service (device restart) via a crafted packet on (1) TCP port 23, (2) UDP port 161, or (3) TCP port 513.Show less
1Emerson
1Deltav
Apr 29, 2026
Oct 1, 2012
N/A· v4
N/A· v3
5.0 MEDIUM· v2
Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (daemon crash) via a long string to an unspecified port.