Записи Emerson
85 опубликованных записей вендора emerson.
Профиль для исследователя
- Попали в KEV
- 0 · 0 %
- С эксплойтом
- 0 · 0 %
- Pre-auth RCE
- 13
- С записью об исправлении
- 0 %
- Медиана: публикация → KEV
- Ни одна запись не попала в KEV
Повторяющиеся классы
- CWE-798 Use of Hard-coded Credentials6
- CWE-306 Missing Authentication for Critical Function5
- CWE-20 Improper Input Validation4
- CWE-22 Improper Limitation of a Pathname to a Restricted Directory ('Path Traversal')4
- CWE-284 Improper Access Control4
- CWE-345 Insufficient Verification of Data Authenticity4
Классы уязвимостей, которые чаще всего встречаются у этого вендора: куда смотреть.
CWEВсе записи
85 записей| Срочность | CVE | Уязвимость | Критичность | KEV | EPSS | Опубликовано |
|---|---|---|---|---|---|---|
45В плане | CVE-2021-45427Эксплойта нет | Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal.emerson · xweb300d evo firmware · CWE-22 | Критическая9,8 | — | 19,2 % | 30 дек. 2021 г. |
44В плане | CVE-2021-45420Proof of concept | Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgiemerson · dixell xweb-500 firmware · CWE-200 | Критическая9,8 | — | 17,6 % | 14 февр. 2022 г. |
42В плане | CVE-2013-2810Эксплойта нет | Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with softwaemerson · dl 8000 remote terminal unit firmware · CWE-77 | Критическая10,0 | — | 6,0 % | 8 дек. 2014 г. |
42В плане | CVE-2013-0689Эксплойта нет | The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and emerson · roc 800l remote terminal unit · CWE-94 | Критическая10,0 | — | 5,0 % | 3 окт. 2013 г. |
41В плане | CVE-2013-0692Эксплойта нет | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlieenea · ose · CWE-264 | Критическая10,0 | — | 4,9 % | 3 окт. 2013 г. |
41В плане | CVE-2013-0693Эксплойта нет | The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlieenea · ose · CWE-200 | Критическая10,0 | — | 3,3 % | 3 окт. 2013 г. |
40В плане | CVE-2016-8348Эксплойта нет | An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior.emerson · liebert sitescan web · CWE-611 | Критическая9,8 | — | 3,5 % | 13 февр. 2017 г. |
40В плане | CVE-2018-14804Эксплойта нет | Emerson AMS Device Manager v12.0 to v13.5.emerson · ams device manager · CWE-284 | Критическая9,8 | — | 3,5 % | 1 окт. 2018 г. |
40В плане | CVE-2020-10640Эксплойта нет | ICSA-20-140-02 Emerson OpenEnterpriseemerson · openenterprise scada server · CWE-306 | Критическая9,8 | — | 3,1 % | 24 февр. 2022 г. |
40В плане | CVE-2020-6970Эксплойта нет | A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are emerson · openenterprise scada server · CWE-122 | Критическая9,8 | — | 2,6 % | 19 февр. 2020 г. |
40В плане | CVE-2018-11691Эксплойта нет | Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switcemerson · ve6046 firmware · CWE-798 | Критическая9,8 | — | 2,3 % | 14 мая 2019 г. |
40В плане | CVE-2021-27459Эксплойта нет | A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer.emerson · x-stream enhanced xegp firmware · CWE-434 | Критическая9,8 | — | 1,8 % | 20 мая 2021 г. |
40В плане | CVE-2020-12030Эксплойта нет | Emerson WirelessHART Gatewayemerson · wireless 1410 gateway firmware · CWE-284 | Критическая10,0 | — | 1,1 % | 29 сент. 2021 г. |
39Наблюдать | CVE-2023-46687Эксплойта нет | Emerson Rosemount GC370XA, GC700XA, GC1500XA Command Injectionemerson · gc370xa firmware · CWE-77 | Критическая9,8 | — | 0,9 % | 9 февр. 2024 г. |
39Наблюдать | CVE-2023-49716Эксплойта нет | Emerson Rosemount GC370XA, GC700XA, GC1500XA Command Injectionemerson · gc370xa firmware · CWE-77 | Критическая9,8 | — | 0,6 % | 9 февр. 2024 г. |
39Наблюдать | CVE-2022-30264Эксплойта нет | The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations.emerson · dl8000 firmware · CWE-345 | Критическая9,8 | — | 0,5 % | 16 авг. 2022 г. |
37Наблюдать | CVE-2013-0694Эксплойта нет | The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with soemerson · dl 8000 remote terminal unit · CWE-255 | Критическая9,0 | — | 2,6 % | 3 окт. 2013 г. |
37Наблюдать | CVE-2023-1935Эксплойта нет | ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or cemerson · roc809 firmware · CWE-287 | Критическая9,4 | — | 0,7 % | 2 авг. 2023 г. |
36Наблюдать | CVE-2019-10967Эксплойта нет | In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server iemerson · ovation ocr400 firmware · CWE-121 | Высокая8,8 | — | 3,7 % | 28 мая 2019 г. |
36Наблюдать | CVE-2019-10965Эксплойта нет | In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server inemerson · ovation ocr400 firmware · CWE-787 | Высокая8,8 | — | 3,6 % | 28 мая 2019 г. |
36Наблюдать | CVE-2020-19417Эксплойта нет | Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasksemerson · wireless 1420 gateway firmware | Высокая8,8 | — | 2,7 % | 10 мар. 2021 г. |
36Наблюдать | CVE-2018-14795Эксплойта нет | DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace emerson · deltav · CWE-23 | Высокая8,8 | — | 2,2 % | 21 авг. 2018 г. |
36Наблюдать | CVE-2023-43609Эксплойта нет | Emerson Rosemount GC370XA, GC700XA, GC1500XA Improper Authorizationemerson · gc370xa firmware · CWE-863 | Критическая9,1 | — | 0,5 % | 9 февр. 2024 г. |
35Наблюдать | CVE-2021-42542Эксплойта нет | Emerson WirelessHART Gatewayemerson · wireless 1410 gateway firmware · CWE-22 | Высокая8,8 | — | 1,5 % | 22 окт. 2021 г. |
35Наблюдать | CVE-2021-42540Эксплойта нет | Emerson WirelessHART Gatewayemerson · wireless 1410 gateway firmware · CWE-123 | Высокая8,8 | — | 1,0 % | 22 окт. 2021 г. |
- CVE-2021-4542745В плане
Emerson XWEB 300D EVO 3.0.7--3ee403 is affected by: unauthenticated arbitrary file deletion due to path traversal.
КритическаяCVSS 9,8Эксплойта нетEPSS 19 %emerson · xweb300d evo firmware30 дек. 2021 г.
- CVE-2021-4542044В плане
Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logo_extra_upload.cgi, /cgi-bin/cal_save.cgi
КритическаяCVSS 9,8Proof of conceptEPSS 18 %emerson · dixell xweb-500 firmware14 февр. 2022 г.
- CVE-2013-281042В плане
Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with softwa
КритическаяCVSS 10,0Эксплойта нетEPSS 6 %emerson · dl 8000 remote terminal unit firmware8 дек. 2014 г.
- CVE-2013-068942В плане
The TFTP server on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %emerson · roc 800l remote terminal unit3 окт. 2013 г.
- CVE-2013-069241В плане
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlie
КритическаяCVSS 10,0Эксплойта нетEPSS 5 %enea · ose3 окт. 2013 г.
- CVE-2013-069341В плане
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlie
КритическаяCVSS 10,0Эксплойта нетEPSS 3 %enea · ose3 окт. 2013 г.
- CVE-2016-834840В плане
An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %emerson · liebert sitescan web13 февр. 2017 г.
- CVE-2018-1480440В плане
Emerson AMS Device Manager v12.0 to v13.5.
КритическаяCVSS 9,8Эксплойта нетEPSS 4 %emerson · ams device manager1 окт. 2018 г.
- CVE-2020-1064040В плане
ICSA-20-140-02 Emerson OpenEnterprise
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %emerson · openenterprise scada server24 февр. 2022 г.
- CVE-2020-697040В плане
A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are
КритическаяCVSS 9,8Эксплойта нетEPSS 3 %emerson · openenterprise scada server19 февр. 2020 г.
- CVE-2018-1169140В плане
Emerson DeltaV Smart Switch Command Center application, available in versions 11.3.x and 12.3.1, was unable to change the DeltaV Smart Switc
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %emerson · ve6046 firmware14 мая 2019 г.
- CVE-2021-2745940В плане
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer.
КритическаяCVSS 9,8Эксплойта нетEPSS 2 %emerson · x-stream enhanced xegp firmware20 мая 2021 г.
- CVE-2020-1203040В плане
Emerson WirelessHART Gateway
КритическаяCVSS 10,0Эксплойта нетEPSS 1 %emerson · wireless 1410 gateway firmware29 сент. 2021 г.
- CVE-2023-4668739Наблюдать
Emerson Rosemount GC370XA, GC700XA, GC1500XA Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %emerson · gc370xa firmware9 февр. 2024 г.
- CVE-2023-4971639Наблюдать
Emerson Rosemount GC370XA, GC700XA, GC1500XA Command Injection
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %emerson · gc370xa firmware9 февр. 2024 г.
- CVE-2022-3026439Наблюдать
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations.
КритическаяCVSS 9,8Эксплойта нетEPSS 1 %emerson · dl8000 firmware16 авг. 2022 г.
- CVE-2013-069437Наблюдать
The Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with so
КритическаяCVSS 9,0Эксплойта нетEPSS 3 %emerson · dl 8000 remote terminal unit3 окт. 2013 г.
- CVE-2023-193537Наблюдать
ROC800-Series RTU devices are vulnerable to an authentication bypass, which could allow an attacker to gain unauthorized access to data or c
КритическаяCVSS 9,4Эксплойта нетEPSS 1 %emerson · roc809 firmware2 авг. 2023 г.
- CVE-2019-1096736Наблюдать
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a stack-based buffer overflow vulnerability in the embedded third-party FTP server i
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %emerson · ovation ocr400 firmware28 мая 2019 г.
- CVE-2019-1096536Наблюдать
In Emerson Ovation OCR400 Controller 3.3.1 and earlier, a heap-based buffer overflow vulnerability in the embedded third-party FTP server in
ВысокаяCVSS 8,8Эксплойта нетEPSS 4 %emerson · ovation ocr400 firmware28 мая 2019 г.
- CVE-2020-1941736Наблюдать
Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform administrative tasks
ВысокаяCVSS 8,8Эксплойта нетEPSS 3 %emerson · wireless 1420 gateway firmware10 мар. 2021 г.
- CVE-2018-1479536Наблюдать
DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace
ВысокаяCVSS 8,8Эксплойта нетEPSS 2 %emerson · deltav21 авг. 2018 г.
- CVE-2023-4360936Наблюдать
Emerson Rosemount GC370XA, GC700XA, GC1500XA Improper Authorization
КритическаяCVSS 9,1Эксплойта нетEPSS 0 %emerson · gc370xa firmware9 февр. 2024 г.
- CVE-2021-4254235Наблюдать
Emerson WirelessHART Gateway
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %emerson · wireless 1410 gateway firmware22 окт. 2021 г.
- CVE-2021-4254035Наблюдать
Emerson WirelessHART Gateway
ВысокаяCVSS 8,8Эксплойта нетEPSS 1 %emerson · wireless 1410 gateway firmware22 окт. 2021 г.