CVE-2022-29965
Last modified
CVE-2022-29965 is a medium-severity vulnerability rated 5.5/10 on the CVSS scale. The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. EPSS estimates a 0.17% chance of exploitation in the next 30 days.
Description
The Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. Access to privileged operations on the maintenance port TELNET interface (23/TCP) on M-series and SIS (CSLS/LSNB/LSNG) nodes is controlled by means of utility passwords. These passwords are generated using a deterministic, insecure algorithm using a single seed value composed of a day/hour/minute timestamp with less than 16 bits of entropy. The seed value is fed through a lookup table and a series of permutation operations resulting in three different four-character passwords corresponding to different privilege levels. An attacker can easily reconstruct these passwords and thus gain access to privileged maintenance operations. NOTE: this is different from CVE-2014-2350.
Metrics
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
Weakness Enumeration
Affected Software
| Vendor | Product | Versions |
|---|---|---|
| Emerson | Deltav Distributed Control System | <= 2022-04-29 |
| Emerson | Deltav Distributed Control System Sq Controller Firmware | <= 2022-04-29 |
| Emerson | Deltav Distributed Control System Sx Controller Firmware | <= 2022-04-29 |
| Emerson | Se4002s1t2b6 High Side 40-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4003s2b4 16-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4003s2b524-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4017p0 H1 I\/O Interface Card And Terminl Block Firmware | <= 2022-04-29 |
| Emerson | Se4017p1 H1 I\/O Card With Integrated Power Firmware | <= 2022-04-29 |
| Emerson | Se4019p0 Simplex H1 4-Port Plus Fieldbus I\/O Interface With Terminalblock Firmware | <= 2022-04-29 |
| Emerson | Se4026 Virtual I\/O Module 2 Firmware | <= 2022-04-29 |
| Emerson | Se4027 Virtual I\/O Module 2 Firmware | <= 2022-04-29 |
| Emerson | Se4032s1t2b8 High Side 40-Pin Do Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4037p0 H1 I\/O Interface Card And Terminl Block Firmware | <= 2022-04-29 |
| Emerson | Se4037p1 Redundant H1 I\/O Card With Integrated Power And Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4039p0 Redundant H1 4-Port Plus Fieldbus I\/O Interface With Terminalblock Firmware | <= 2022-04-29 |
| Emerson | Se4052s1t2b6 High Side 40-Pin Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4082s1t2b8 High Side 40-Pin Do Mass I\/O Terminal Block Firmware | <= 2022-04-29 |
| Emerson | Se4100 Simplex Ethernet I\/O Card \(Eioc\) Assembly Firmware | <= 2022-04-29 |
| Emerson | Se4101 Simplex Ethernet I\/O Card \(Eioc\) Assembly Firmware | <= 2022-04-29 |
| Emerson | Se4801t0x Redundant Wireless I\/O Card Firmware | <= 2022-04-29 |
| Emerson | Ve4103 Modbus Tcp Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4104 Ethernet\/Ip Control Tag Integration For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4105 Ethernet\/Ip Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4106 Opc-Ua Client For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
| Emerson | Ve4107 Iec 61850 Mms Interface For Ethernet Connected I\/O \(Eioc\) Firmware | <= 2022-04-29 |
References
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
- https://www.cisa.gov/uscert/ics/advisories/icsa-22-181-03Third Party Advisory, US Government Resource
- https://www.forescout.com/blog/Third Party Advisory
Timeline
- Published
- Last Modified
- Status
- Modified
Frequently Asked Questions
What is CVE-2022-29965?
How severe is CVE-2022-29965?
How do I fix CVE-2022-29965?
How Strix Helps
- How Strix found a critical auth bypass in etcdStrix autonomously discovered a critical authentication bypass in etcd, later designated CVE-2026-33413.
- Autonomous PentestingAI agents that find and validate exploitable vulnerabilities like this one across your applications.
- PR ReviewsPentest every pull request so vulnerable code is caught before it ships to production.
- AI Penetration TestingHow AI-driven penetration testing continuously covers your attack surface.
Related CVEs from 2022
- CVE-2022-29959Emerson OpenBSI through 2022-04-29 mishandles credential sto…5.5
- CVE-2022-2996A flaw was found in the python-scciclient when making an HTT…7.4
- CVE-2022-29960Emerson OpenBSI through 2022-04-29 uses weak cryptography. I…5.5
- CVE-2022-29962The Emerson DeltaV Distributed Control System (DCS) controll…5.5
- CVE-2022-29963The Emerson DeltaV Distributed Control System (DCS) controll…5.5
- CVE-2022-29964The Emerson DeltaV Distributed Control System (DCS) controll…5.5
- CVE-2022-29967static_compressed_inmemory_website_callback.c in Glewlwyd th…7.5
- CVE-2022-29968An issue was discovered in the Linux kernel through 5.17.5. …7.8
- CVE-2022-29969The RSS extension before 2022-04-29 for MediaWiki allows XSS…6.1
- CVE-2022-2997Session Fixation in GitHub repository snipe/snipe-it prior t…8
- CVE-2022-29970Sinatra before 2.2.0 does not validate that the expanded pat…7.5
- CVE-2022-29971An argument injection vulnerability in the browser-based aut…7.8
Are you affected by CVE-2022-29965?
Run a free Strix scan to check your systems for this vulnerability.
Scan your code nowSource: NVD / NIST
