Emerson
Emerson Deltav: vulnerabilidades y CVE
Emerson Deltav tiene 15 vulnerabilidades publicadas, 0 de ellas en los últimos 12 meses. 0 son críticas y 0 figuran en el catálogo de explotación activa de CISA.
CVE15
Últimos 12 meses0
Críticas0
Explotadas activamente0
Todas las vulnerabilidades en el catálogo →⭐ Seguir esta tecnología
Últimas vulnerabilidades
| CVE | Severidad | EPSS | Explotación activa | Publicada | Descripción |
|---|---|---|---|---|---|
| CVE-2021-44463 | Alta (7.3) | 0.26% | — | 28 ene 2022 | Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are… |
| CVE-2018-19021 | Media (6.5) | 0.72% | — | 25 ene 2019 | A specially crafted script could bypass the authentication of a maintenance port of Emerson DeltaV DCS Versions 11.3.1, 11.3.2, 12.3.1, 13.3.1, 14.3, R5.1, R6 and prior, which may allow an attacker to cause a denial of… |
| CVE-2018-14797 | Alta (7.8) | 1.7% | — | 23 ago 2018 | Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 allow a specially crafted DLL file to be placed in the search path and loaded as an internal and valid DLL, which may allow arbitrary code execution. |
| CVE-2018-14791 | Alta (7.8) | 0.36% | — | 23 ago 2018 | Emerson DeltaV DCS versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, R5 may allow non-administrative users to change executable and library files on the affected products. |
| CVE-2018-14795 | Alta (8.8) | 2.2% | — | 21 ago 2018 | DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable due to improper path validation which may allow an attacker to replace executable files. |
| CVE-2018-14793 | Alta (8.8) | 1.0% | — | 21 ago 2018 | DeltaV Versions 11.3.1, 12.3.1, 13.3.0, 13.3.1, and R5 is vulnerable to a buffer overflow exploit through an open communication port to allow arbitrary code execution. |
| CVE-2016-9345 | Media (6.8) | 0.43% | — | 13 feb 2017 | An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control… |
| CVE-2014-2350 | Alta (7.5) | 1.3% | — | 22 may 2014 | Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that… |
| CVE-2014-2349 | Media (4.6) | 0.66% | — | 22 may 2014 | Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that… |
| CVE-2012-3035 | Media (5) | 2.2% | — | 1 oct 2012 | Buffer overflow in Emerson DeltaV 9.3.1 and 10.3 through 11.3.1 allows remote attackers to cause a denial of service (daemon crash) via a long string to an unspecified port. |
| CVE-2012-1818 | Media (6.4) | 1.9% | — | 8 jun 2012 | An unspecified ActiveX control in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to overwrite arbitrary files via unknown… |
| CVE-2012-1817 | Alta (7.5) | 4.0% | — | 8 jun 2012 | Buffer overflow in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows user-assisted remote attackers to execute arbitrary code or cause a… |
| CVE-2012-1816 | Media (5) | 1.9% | — | 8 jun 2012 | PORTSERV.exe in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to cause a denial of service (daemon crash) via a crafted… |
| CVE-2012-1815 | Alta (7.5) | 1.5% | — | 8 jun 2012 | SQL injection vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to execute arbitrary SQL commands via… |
| CVE-2012-1814 | Media (4.3) | 1.3% | — | 8 jun 2012 | Cross-site scripting (XSS) vulnerability in Emerson DeltaV and DeltaV Workstations 9.3.1, 10.3.1, 11.3, and 11.3.1 and DeltaV ProEssentials Scientific Graph 5.0.0.6 allows remote attackers to inject arbitrary web script… |
Otros productos de Emerson
Wireless 1420 Gateway Firmware · 8X-stream Enhanced Xegp Firmware · 7Wireless 1410 Gateway Firmware · 7X-stream Enhanced Xefd Firmware · 7X-stream Enhanced Xegk Firmware · 7X-stream Enhanced Xexf Firmware · 7Deltav Workstation · 6Wireless 1410d Gateway Firmware · 6Valvelink · 6Se4801t0x Redundant Wireless I/O Card Firmware · 6Deltav Distributed Control System SX Controller Firmware · 5Deltav Distributed Control System SQ Controller Firmware · 5