emerson CVE Vulnerabilities & Metrics

Focus on emerson vulnerabilities and metrics.

Last updated: 08 Mar 2025, 23:25 UTC

About emerson Security Exposure

This page consolidates all known Common Vulnerabilities and Exposures (CVEs) associated with emerson. We track both calendar-based metrics (using fixed periods) and rolling metrics (using gliding windows) to give you a comprehensive view of security trends and risk evolution. Use these insights to assess risk and plan your patching strategy.

For a broader perspective on cybersecurity threats, explore the comprehensive list of CVEs by vendor and product. Stay updated on critical vulnerabilities affecting major software and hardware providers.

Global CVE Overview

Total emerson CVEs: 64
Earliest CVE date: 08 Jun 2012, 18:55 UTC
Latest CVE date: 20 Feb 2024, 15:15 UTC

Latest CVE reference: CVE-2024-1156

Rolling Stats

30-day Count (Rolling): 0
365-day Count (Rolling): 0

Calendar-based Variation

Calendar-based Variation compares a fixed calendar period (e.g., this month versus the same month last year), while Rolling Growth Rate uses a continuous window (e.g., last 30 days versus the previous 30 days) to capture trends independent of calendar boundaries.

Variations & Growth

Month Variation (Calendar): 0%
Year Variation (Calendar): -100.0%

Month Growth Rate (30-day Rolling): 0.0%
Year Growth Rate (365-day Rolling): -100.0%

Monthly CVE Trends (current vs previous Year)

Annual CVE Trends (Last 20 Years)

Critical emerson CVEs (CVSS ≥ 9) Over 20 Years

CVSS Stats

Average CVSS: 4.87

Max CVSS: 10.0

Critical CVEs (≥9): 9

CVSS Range vs. Count

Range Count
0.0-3.9 21
4.0-6.9 39
7.0-8.9 9
9.0-10.0 9

CVSS Distribution Chart

Top 5 Highest CVSS emerson CVEs

These are the five CVEs with the highest CVSS scores for emerson, sorted by severity first and recency.

All CVEs for emerson

CVE-2024-1156 emerson vulnerability CVSS: 0 20 Feb 2024, 15:15 UTC

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

CVE-2024-1155 emerson vulnerability CVSS: 0 20 Feb 2024, 15:15 UTC

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

CVE-2023-51761 emerson vulnerability CVSS: 0 09 Feb 2024, 04:15 UTC

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

CVE-2023-49716 emerson vulnerability CVSS: 0 09 Feb 2024, 04:15 UTC

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

CVE-2023-46687 emerson vulnerability CVSS: 0 09 Feb 2024, 04:15 UTC

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

CVE-2023-43609 emerson vulnerability CVSS: 0 09 Feb 2024, 04:15 UTC

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

CVE-2023-1935 emerson vulnerability CVSS: 0 02 Aug 2023, 23:15 UTC

ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.

CVE-2022-30260 emerson vulnerability CVSS: 0 26 Dec 2022, 06:15 UTC

Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.

CVE-2022-30262 emerson vulnerability CVSS: 0 17 Aug 2022, 15:15 UTC

The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images were found to have no authentication (in the form of firmware signing) and only relied on insecure checksums for regular integrity checks.

CVE-2022-30264 emerson vulnerability CVSS: 0 16 Aug 2022, 13:15 UTC

The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.

CVE-2022-29959 emerson vulnerability CVSS: 0 16 Aug 2022, 13:15 UTC

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

CVE-2022-29965 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.

CVE-2022-29964 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

CVE-2022-29963 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

CVE-2022-29962 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

CVE-2022-29960 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

CVE-2022-29957 emerson vulnerability CVSS: 0 26 Jul 2022, 22:15 UTC

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

CVE-2020-16235 emerson vulnerability CVSS: 2.1 19 May 2022, 18:15 UTC

Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.

CVE-2020-10640 emerson vulnerability CVSS: 10.0 24 Feb 2022, 19:15 UTC

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

CVE-2020-10636 emerson vulnerability CVSS: 5.0 24 Feb 2022, 19:15 UTC

Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.

CVE-2020-10632 emerson vulnerability CVSS: 5.0 24 Feb 2022, 19:15 UTC

Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

CVE-2021-45421 emerson vulnerability CVSS: 5.0 14 Feb 2022, 14:15 UTC

Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced

CVE-2021-45420 emerson vulnerability CVSS: 10.0 14 Feb 2022, 14:15 UTC

Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced

CVE-2021-44463 emerson vulnerability CVSS: 6.9 28 Jan 2022, 20:15 UTC

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

CVE-2021-26264 emerson vulnerability CVSS: 4.9 28 Jan 2022, 20:15 UTC

A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

CVE-2021-45427 emerson vulnerability CVSS: 7.5 30 Dec 2021, 12:15 UTC

Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

CVE-2021-42542 emerson vulnerability CVSS: 6.5 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.

CVE-2021-42540 emerson vulnerability CVSS: 6.5 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

CVE-2021-42539 emerson vulnerability CVSS: 6.5 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.

CVE-2021-42538 emerson vulnerability CVSS: 6.5 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

CVE-2021-42536 emerson vulnerability CVSS: 4.0 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

CVE-2021-38485 emerson vulnerability CVSS: 6.5 22 Oct 2021, 14:15 UTC

The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.

CVE-2020-12030 emerson vulnerability CVSS: 6.8 29 Sep 2021, 20:15 UTC

There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

CVE-2021-29298 emerson vulnerability CVSS: 2.6 30 Jul 2021, 19:15 UTC

Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe"in the module "fxVPStatcTcp.dll".

CVE-2021-29297 emerson vulnerability CVSS: 2.6 30 Jul 2021, 19:15 UTC

Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe" in the module "MSVCR100.dll".

CVE-2021-27467 emerson vulnerability CVSS: 5.8 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web interface allows an attacker to route click or keystroke to another page provided by the attacker to gain unauthorized access to sensitive information.

CVE-2021-27465 emerson vulnerability CVSS: 4.3 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do not validate webpage input, which could allow an attacker to inject arbitrary HTML code into a webpage. This would allow an attacker to modify the page and display incorrect or undesirable data.

CVE-2021-27463 emerson vulnerability CVSS: 5.0 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications utilize persistent cookies where the session cookie attribute is not properly invalidated, allowing an attacker to intercept the cookies and gain access to sensitive information.

CVE-2021-27461 emerson vulnerability CVSS: 5.0 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.

CVE-2021-27459 emerson vulnerability CVSS: 7.5 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

CVE-2021-27457 emerson vulnerability CVSS: 5.0 20 May 2021, 12:15 UTC

A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

CVE-2020-19419 emerson vulnerability CVSS: 5.0 10 Mar 2021, 18:15 UTC

Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

CVE-2020-19417 emerson vulnerability CVSS: 9.0 10 Mar 2021, 18:15 UTC

Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application.

CVE-2020-12525 emerson vulnerability CVSS: 6.8 22 Jan 2021, 19:15 UTC

M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserialization of untrusted data in its project storage.

CVE-2020-27254 emerson vulnerability CVSS: 5.0 21 Dec 2020, 18:15 UTC

Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.

CVE-2020-6971 emerson vulnerability CVSS: 4.6 05 Mar 2020, 21:15 UTC

In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.

CVE-2020-6970 emerson vulnerability CVSS: 7.5 19 Feb 2020, 21:15 UTC

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

CVE-2019-13524 emerson vulnerability CVSS: 7.8 16 Jan 2020, 18:15 UTC

GE PACSystems RX3i CPE100/115: All versions prior to R9.85,CPE302/305/310/330/400/410: All versions prior to R9.90,CRU/320 All versions(End of Life) may allow an attacker sending specially manipulated packets to cause the module state to change to halt-mode, resulting in a denial-of-service condition. An operator must reboot the CPU module after removing battery or energy pack to recover from halt-mode.

CVE-2019-10967 emerson vulnerability CVSS: 6.5 28 May 2019, 22:29 UTC

In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers, leading to remote code execution and escalation of privileges.

CVE-2019-10965 emerson vulnerability CVSS: 6.5 28 May 2019, 22:29 UTC

In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long command to the FTP service, which may cause memory corruption that halts the controller or leads to remote code execution and escalation of privileges.

CVE-2019-12167 emerson vulnerability CVSS: 4.3 22 May 2019, 18:29 UTC

httpGetSet/httpGet.htm on Emerson Network Power Liebert Challenger 5.1E0.5 devices allows XSS via the statusstr parameter.

CVE-2018-11691 emerson vulnerability CVSS: 10.0 14 May 2019, 16:29 UTC

Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson released patches for DeltaV workstations to address this issue, and the patches can be downloaded from Emerson’s Guardian Support Portal. Please refer to the DeltaV Security Notification DSN19003 (KBA NK-1900-0808) for more information about this issue. DeltaV versions 13.3 and higher use the Network Device Command Center application to manage DeltaV Smart Switches, and this newer application is not impacted by this issue. After patching the Smart Switch Command Center, users are required to either commission the DeltaV Smart Switches or change password using the tool.

CVE-2018-19021 emerson vulnerability CVSS: 3.3 25 Jan 2019, 20:29 UTC

A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of service.

CVE-2018-14808 emerson vulnerability CVSS: 4.0 01 Oct 2018, 15:29 UTC

Emerson AMS Device Manager v12.0 to v13.5. Non-administrative users are able to change executable and library files on the affected products.

CVE-2018-14804 emerson vulnerability CVSS: 7.5 01 Oct 2018, 15:29 UTC

Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

CVE-2018-14797 emerson vulnerability CVSS: 6.8 23 Aug 2018, 19:29 UTC

Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.

CVE-2018-14791 emerson vulnerability CVSS: 4.6 23 Aug 2018, 19:29 UTC

Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affected products.

CVE-2018-14795 emerson vulnerability CVSS: 6.5 21 Aug 2018, 14:29 UTC

DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.

CVE-2018-14793 emerson vulnerability CVSS: 5.8 21 Aug 2018, 14:29 UTC

DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to allow arbitrary code execution.

CVE-2018-5452 emerson vulnerability CVSS: 5.0 07 Mar 2018, 18:29 UTC

A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based buffer overflow vulnerability caused by sending crafted packets on Port 20547 could force the PLC to change its state into halt mode.

CVE-2016-9347 emerson vulnerability CVSS: 5.4 13 Feb 2017, 21:59 UTC

An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell) functionality enabled unnecessarily.

CVE-2016-9345 emerson vulnerability CVSS: 4.9 13 Feb 2017, 21:59 UTC

An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control system.

CVE-2016-8348 emerson vulnerability CVSS: 7.5 13 Feb 2017, 21:59 UTC

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

CVE-2015-1008 emerson vulnerability CVSS: 6.5 26 May 2015, 01:59 UTC

SQL injection vulnerability in Emerson AMS Device Manager before 13 allows remote authenticated users to gain privileges via malformed input.

CVE-2013-2810 emerson vulnerability CVSS: 10.0 08 Dec 2014, 11:59 UTC

Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary commands via a TCP replay attack.

CVE-2014-2350 emerson vulnerability CVSS: 7.5 22 May 2014, 20:55 UTC

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

CVE-2014-2349 emerson vulnerability CVSS: 4.6 22 May 2014, 20:55 UTC

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 allows local users to modify or read configuration files by leveraging engineering-level privileges.

CVE-2013-6030 emerson vulnerability CVSS: 5.0 24 Jan 2014, 04:38 UTC

Directory traversal vulnerability on the Emerson Network Power Avocent MergePoint Unity 2016 (aka MPU2016) KVM switch with firmware 1.9.16473 allows remote attackers to read arbitrary files via unspecified vectors, as demonstrated by reading the /etc/passwd file.

CVE-2013-0694 emerson vulnerability CVSS: 9.0 03 Oct 2013, 11:04 UTC

The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier have hardcoded credentials in a ROM, which makes it easier for remote attackers to obtain shell access to the underlying OS by leveraging knowledge of the ROM contents from a product installation elsewhere.

CVE-2013-0693 emerson vulnerability CVSS: 10.0 03 Oct 2013, 11:04 UTC

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.

CVE-2013-0692 emerson vulnerability CVSS: 10.0 03 Oct 2013, 11:04 UTC

The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.

CVE-2013-0689 emerson vulnerability CVSS: 10.0 03 Oct 2013, 11:04 UTC

The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to upload files and consequently execute arbitrary code via unspecified vectors.

CVE-2012-3035 emerson vulnerability CVSS: 5.0 01 Oct 2012, 18:55 UTC

Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (daemon crash) via a long string to an unspecified port.

CVE-2012-1818 emerson vulnerability CVSS: 6.4 08 Jun 2012, 18:55 UTC

An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to overwrite arbitrary files via unknown vectors.

CVE-2012-1817 emerson vulnerability CVSS: 7.5 08 Jun 2012, 18:55 UTC

Buffer overflow in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows user-assisted remote attackers to execute arbitrary code or cause a denial of service (daemon crash) via an invalid field in a project file.

CVE-2012-1816 emerson vulnerability CVSS: 5.0 08 Jun 2012, 18:55 UTC

PORTSERV.exe in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to cause a denial of service (daemon crash) via a crafted (1) TCP or (2) UDP packet to port 111.

CVE-2012-1815 emerson vulnerability CVSS: 7.5 08 Jun 2012, 18:55 UTC

SQL injection vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to execute arbitrary SQL commands via unspecified vectors.

CVE-2012-1814 emerson vulnerability CVSS: 4.3 08 Jun 2012, 18:55 UTC

Cross-site scripting (XSS) vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to inject arbitrary web script or HTML via unspecified vectors.