VYPR

Deltav Distributed Control System

by Emerson

CVEs (8)

  • CVE-2021-44463HigJan 28, 2022
    risk 0.53cvss 8.1epss 0.00

    Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

  • CVE-2022-30260HigDec 26, 2022
    risk 0.51cvss 7.8epss 0.00

    Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC…

  • CVE-2022-29957HigJul 26, 2022
    risk 0.51cvss 7.8epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk…

  • CVE-2021-26264MedJan 28, 2022
    risk 0.40cvss 6.1epss 0.00

    A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

  • CVE-2022-29965MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility…

  • CVE-2022-29964MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. WIOC SSH provides access to a shell as root, DeltaV, or backup via hardcoded credentials. NOTE: this is different from CVE-2014-2350.

  • CVE-2022-29963MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from…

  • CVE-2022-29962MedJul 26, 2022
    risk 0.36cvss 5.5epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from…