VYPR

Vendor CVEs

Emerson

All CVEs

114 total · sorted by risk
  • CVE-2023-27482CriMar 8, 2023
    risk 0.71cvss 10.0epss 0.72

    homeassistant is an open source home automation tool. A remotely exploitable vulnerability bypassing authentication for accessing the Supervisor API through Home Assistant has been discovered. This impacts all Home Assistant installation types that use the Supervisor 2023.01.1…

  • CVE-2020-10640CriFeb 24, 2022
    risk 0.65cvss 10.0epss 0.03

    Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

  • CVE-2021-45420CriFeb 14, 2022
    risk 0.65cvss 9.8epss 0.18

    Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi, and /cgi-bin/lo_utils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism,…

  • CVE-2021-45427CriDec 30, 2021
    risk 0.65cvss 9.8epss 0.19

    Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal. An attacker can browse and delete files without any authentication due to incorrect access control and directory traversal.

  • CVE-2020-12030CriSep 29, 2021
    risk 0.65cvss 10.0epss 0.01

    There is a flaw in the code used to configure the internal gateway firewall when the gateway's VLAN feature is enabled. If a user enables the VLAN setting, the internal gateway firewall becomes disabled resulting in exposure of all ports used by the gateway.

  • CVE-2023-46687CriFeb 9, 2024
    risk 0.64cvss 9.8epss 0.01

    In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

  • CVE-2022-30264CriAug 16, 2022
    risk 0.64cvss 9.8epss 0.01

    The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer…

  • CVE-2021-27459CriMay 20, 2021
    risk 0.64cvss 9.8epss 0.02

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.

  • CVE-2020-6970CriFeb 19, 2020
    risk 0.64cvss 9.8epss 0.03

    A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise…

  • CVE-2018-11691CriMay 14, 2019
    risk 0.64cvss 9.8epss 0.02

    Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switches’ management password upon commissioning. Emerson released patches for DeltaV workstations to address this issue, and the patches can…

  • CVE-2018-14804CriOct 1, 2018
    risk 0.64cvss 9.8epss 0.04

    Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.

  • CVE-2017-7931CriJun 6, 2018
    risk 0.64cvss 9.8epss 0.03

    In ABB IP GATEWAY 3.39 and prior, by accessing a specific uniform resource locator (URL) on the web server, a malicious user is able to access the configuration files and application pages without authentication.

  • CVE-2018-8840CriApr 18, 2018
    risk 0.64cvss 9.8epss 0.08

    A remote attacker could send a carefully crafted packet in InduSoft Web Studio v8.1 and prior versions, and/or InTouch Machine Edition 2017 v8.1 and prior versions during a tag, alarm, or event related action such as read and write, which may allow remote code execution.

  • CVE-2016-8348CriFeb 13, 2017
    risk 0.64cvss 9.8epss 0.04

    An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents…

  • CVE-2025-52579CriJul 11, 2025
    risk 0.61cvss 9.4epss 0.00

    Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.

  • CVE-2023-1935CriAug 2, 2023
    risk 0.61cvss 9.4epss 0.01

    ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or control of the device and cause a denial-of-service condition.

  • CVE-2019-10967HigMay 28, 2019
    risk 0.58cvss 8.8epss 0.04

    In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long file name from the LIST command to the FTP service, which may cause the service to overwrite buffers,…

  • CVE-2020-10632HigFeb 24, 2022
    risk 0.57cvss 8.8epss 0.00

    Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

  • CVE-2020-19417HigMar 10, 2021
    risk 0.57cvss 8.8epss 0.03

    Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks by sending specially crafted HTTP requests to the application.

  • CVE-2019-10965HigMay 28, 2019
    risk 0.57cvss 8.8epss 0.04

    In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server involves improper handling of a long command to the FTP service, which may cause memory corruption that halts the controller or leads to…

  • CVE-2018-17937HigMar 13, 2019
    risk 0.57cvss 8.8epss 0.03

    gpsd versions 2.90 to 3.17 and microjson versions 1.0 to 1.3, an open source project, allow a stack-based buffer overflow, which may allow remote attackers to execute arbitrary code on embedded platforms via traffic on Port 2947/TCP or crafted JSON inputs.

  • CVE-2018-19017HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.02

    Several use after free vulnerabilities have been identified in CX-Supervisor (Versions 3.42 and prior). When processing project files, the application fails to check if it is referencing freed memory. An attacker could use a specially crafted project file to exploit and execute…

  • CVE-2018-19011HigJan 22, 2019
    risk 0.57cvss 8.8epss 0.02

    CX-Supervisor (Versions 3.42 and prior) can execute code that has been injected into a project file. An attacker could exploit this to execute code under the privileges of the application.

  • CVE-2018-14795HigAug 21, 2018
    risk 0.57cvss 8.8epss 0.02

    DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files.

  • CVE-2018-14793HigAug 21, 2018
    risk 0.57cvss 8.8epss 0.01

    DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to allow arbitrary code execution.

  • CVE-2017-7906HigJun 6, 2018
    risk 0.57cvss 8.8epss 0.01

    In ABB IP GATEWAY 3.39 and prior, the web server does not sufficiently verify that a request was performed by the authenticated user, which may allow an attacker to launch a request impersonating that user.

  • CVE-2022-50930HigJan 13, 2026
    risk 0.55cvss 8.4epss 0.00

    Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code…

  • CVE-2023-51761HigFeb 9, 2024
    risk 0.54cvss 8.3epss 0.01

    In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

  • CVE-2021-44463HigJan 28, 2022
    risk 0.53cvss 8.1epss 0.00

    Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

  • CVE-2021-42542HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure.

  • CVE-2021-42540HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can leverage this logic to overwrite the settings and other key functionality.

  • CVE-2021-42539HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account take over and unapproved settings change.

  • CVE-2021-42538HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled input.

  • CVE-2021-42536HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global variables.

  • CVE-2021-38485HigOct 22, 2021
    risk 0.52cvss 8.0epss 0.01

    The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide malicious config files to replace any file on disk.

  • CVE-2024-1156HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

  • CVE-2024-1155HigFeb 20, 2024
    risk 0.51cvss 7.8epss 0.00

    Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

  • CVE-2022-30260HigDec 26, 2022
    risk 0.51cvss 7.8epss 0.00

    Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC…

  • CVE-2022-30262HigAug 17, 2022
    risk 0.51cvss 7.8epss 0.00

    The Emerson ControlWave 'Next Generation' RTUs through 2022-05-02 mishandle firmware integrity. They utilize the BSAP-IP protocol to transmit firmware updates. Firmware updates are supplied as CAB archive files containing a binary firmware image. In all cases, firmware images…

  • CVE-2022-29957HigJul 26, 2022
    risk 0.51cvss 7.8epss 0.00

    The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk…

  • CVE-2020-6971HigMar 5, 2020
    risk 0.51cvss 7.8epss 0.00

    In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.

  • CVE-2018-19008HigFeb 13, 2019
    risk 0.51cvss 7.8epss 0.02

    The TextEditor 2.0 in ABB CP400 Panel Builder versions 2.0.7.05 and earlier contain a vulnerability in the file parser of the Text Editor wherein the application doesn't properly prevent the insertion of specially crafted files which could allow arbitrary code execution.

  • CVE-2018-14797HigAug 23, 2018
    risk 0.51cvss 7.8epss 0.02

    Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution.

  • CVE-2018-14791HigAug 23, 2018
    risk 0.51cvss 7.8epss 0.00

    Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affected products.

  • CVE-2025-50109HigJul 11, 2025
    risk 0.50cvss 7.7epss 0.00

    Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.

  • CVE-2025-46358HigJul 11, 2025
    risk 0.50cvss 7.7epss 0.00

    Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

  • CVE-2021-45421HigFeb 14, 2022
    risk 0.49cvss 7.5epss 0.01

    Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or…

  • CVE-2021-27461HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.01

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver applications allow access to stored data that can be obtained by using specially crafted URLs.

  • CVE-2021-27457HigMay 20, 2021
    risk 0.49cvss 7.5epss 0.00

    A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.

  • CVE-2020-19419HigMar 10, 2021
    risk 0.49cvss 7.5epss 0.03

    Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device information from the administrator console without authentication.

Page 1 of 3