Medium severity5.3NVD Advisory· Published Jul 30, 2021· Updated Jun 17, 2026
CVE-2021-29298
CVE-2021-29298
Description
Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and application crash via crafted traffic from a Man-in-the-Middle (MITM) attack to the component "FrameworX.exe"in the module "fxVPStatcTcp.dll".
Affected products
3cpe:2.3:a:emerson:proficy_machine_edition:8.0:*:*:*:*:*:*:*+ 1 more
- cpe:2.3:a:emerson:proficy_machine_edition:8.0:*:*:*:*:*:*:*
- (no CPE)range: <=8.0
- Emerson GE Automation/Proficy Machine Editiondescription
Patches
Vulnerability mechanics
References
1- github.com/boofish/GE_Proficy_Machine_Edition_vul/blob/main/vul2/vul2_steps.pdfnvdBroken LinkThird Party Advisory
News mentions
0No linked articles in our index yet.