CVE-2022-29962
Last modified
CVE-2022-29962 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). EPSS estimates a 0.23% chance of exploitation in the next 30 days.
Description
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. FTP has hardcoded credentials (but may often be disabled in production). This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emerson | Deltav Distributed Control System Sq Controller Firmware | <= 2022-04-29 |
| Emerson | Deltav Distributed Control System Sx Controller Firmware | <= 2022-04-29 |
| Emerson | Se4002s1t2b6 High Side 40-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4003s2b4 16-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4003s2b524-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4017p0 H1 I\/O Interface Card And Terminl Block Firmware | <= 2022-04-29 |
| Emerson | Se4017p1 H1 I\/O Card With Integrated Power Firmware | <= 2022-04-29 |
| Emerson | Se4019p0 Simplex H1 4-Port Plus Fieldbus I\/O Interface With Terminalblock Firmware | <= 2022-04-29 |
| Emerson | Se4026 Virtual I\/O Module 2 Firmware | <= 2022-04-29 |
| Emerson | Se4027 Virtual I\/O Module 2 Firmware | <= 2022-04-29 |
| Emerson | Se4032s1t2b8 High Side 40-Pin Do Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4037p0 H1 I\/O Interface Card And Terminl Block Firmware | <= 2022-04-29 |
| Emerson | Se4037p1 Redundant H1 I\/O Card With Integrated Power And Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4039p0 Redundant H1 4-Port Plus Fieldbus I\/O Interface With Terminalblock Firmware | <= 2022-04-29 |
| Emerson | Se4052s1t2b6 High Side 40-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4082s1t2b8 High Side 40-Pin Do Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4100 Simplex Ethernet I\/O Card \(Eioc\) Assembly Firmware | <= 2022-04-29 |
| Emerson | Se4101 Simplex Ethernet I\/O Card \(Eioc\) Assembly Firmware | <= 2022-04-29 |
| Emerson | Se4801t0x Redundant Wireless I\/O Card Firmware | <= 2022-04-29 |
| Emerson | Ve4103 Modbus Tcp Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4104 Ethernet\/Ip Control Tag Integration For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4105 Ethernet\/Ip Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4106 Opc-Ua Client For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29962?
How severe is CVE-2022-29962?
How do I fix CVE-2022-29962?
Are you affected by CVE-2022-29962?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
