VYPR
Medium severity5.5NVD Advisory· Published Jul 26, 2022· Updated Jun 17, 2026

CVE-2022-29960

CVE-2022-29960

Description

Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.

AI Insight

LLM-synthesized narrative grounded in this CVE's description and references.

Affected products

7
  • Emerson/OpenBSI6 versions
    cpe:2.3:a:emerson:openbsi:*:*:*:*:*:*:*:*+ 5 more
    • cpe:2.3:a:emerson:openbsi:*:*:*:*:*:*:*:*range: <5.9
    • cpe:2.3:a:emerson:openbsi:5.9:-:*:*:*:*:*:*
    • cpe:2.3:a:emerson:openbsi:5.9:sp1:*:*:*:*:*:*
    • cpe:2.3:a:emerson:openbsi:5.9:sp2:*:*:*:*:*:*
    • cpe:2.3:a:emerson:openbsi:5.9:sp3:*:*:*:*:*:*
    • (no CPE)range: <=2022-04-29
  • Emerson/OpenBSIdescription

Patches

Vulnerability mechanics

References

3

News mentions

0

No linked articles in our index yet.