Lucene search

K
nvd[email protected]NVD:CVE-2022-29957
HistoryJul 26, 2022 - 10:15 p.m.

CVE-2022-29957

2022-07-2622:15:10
CWE-306
web.nvd.nist.gov
1
emerson deltav
dcs
authentication
proprietary protocols
firmware upgrade
plug-and-play
hawk services
management
cold restart
sis communications
wireless gateway protocol
vulnerability

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

10.4%

The Emerson DeltaV Distributed Control System (DCS) through 2022-04-29 mishandles authentication. It utilizes several proprietary protocols for a wide variety of functionality. These protocols include Firmware upgrade (18508/TCP, 18518/TCP); Plug-and-Play (18510/UDP); Hawk services (18507/UDP); Management (18519/TCP); Cold restart (18512/UDP); SIS communications (12345/TCP); and Wireless Gateway Protocol (18515/UDP). None of these protocols have any authentication features, allowing any attacker capable of communicating with the ports in question to invoke (a subset of) desired functionality.

Affected configurations

Nvd
Node
emersondeltav_distributed_control_systemRange2022-04-29
VendorProductVersionCPE
emersondeltav_distributed_control_system*cpe:2.3:a:emerson:deltav_distributed_control_system:*:*:*:*:*:*:*:*

CVSS3

7.8

Attack Vector

LOCAL

Attack Complexity

LOW

Privileges Required

LOW

User Interaction

NONE

Scope

UNCHANGED

Confidentiality Impact

HIGH

Integrity Impact

HIGH

Availability Impact

HIGH

CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

EPSS

0

Percentile

10.4%

Related for NVD:CVE-2022-29957