CVE-2022-29963

Summary

CVECVE-2022-29963
StatePUBLIC
Assigner[email protected]
Source PriorityCVE Program / NVD first with legacy fallback
Published2022-07-26 22:15:00 UTC
Updated2022-08-04 15:55:00 UTC
DescriptionThe Emerson DeltaV Distributed Control System (DCS) controllers and IO cards through 2022-04-29 misuse passwords. TELNET on port 18550 provides access to a root shell via hardcoded credentials. This affects S-series, P-series, and CIOC/EIOC nodes. NOTE: this is different from CVE-2014-2350.

Risk And Classification

Problem Types: CWE-798

NVD Known Affected Configurations (CPE 2.3)

TypeVendorProductVersionUpdateEditionLanguage
Hardware Emerson Deltav Distributed Control System Sq Controller - All All All
Operating System Emerson Deltav Distributed Control System Sq Controller Firmware All All All All
Hardware Emerson Deltav Distributed Control System Sx Controller - All All All
Operating System Emerson Deltav Distributed Control System Sx Controller Firmware All All All All
Hardware Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block - All All All
Operating System Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4003s2b4 16-pin Mass I/o Terminal Block - All All All
Operating System Emerson Se4003s2b4 16-pin Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4003s2b524-pin Mass I/o Terminal Block - All All All
Operating System Emerson Se4003s2b524-pin Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4017p0 H1 I/o Interface Card And Terminl Block - All All All
Operating System Emerson Se4017p0 H1 I/o Interface Card And Terminl Block Firmware All All All All
Hardware Emerson Se4017p1 H1 I/o Card With Integrated Power - All All All
Operating System Emerson Se4017p1 H1 I/o Card With Integrated Power Firmware All All All All
Hardware Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock - All All All
Operating System Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware All All All All
Hardware Emerson Se4026 Virtual I/o Module 2 - All All All
Operating System Emerson Se4026 Virtual I/o Module 2 Firmware All All All All
Hardware Emerson Se4027 Virtual I/o Module 2 - All All All
Operating System Emerson Se4027 Virtual I/o Module 2 Firmware All All All All
Hardware Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block - All All All
Operating System Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4037p0 H1 I/o Interface Card And Terminl Block - All All All
Operating System Emerson Se4037p0 H1 I/o Interface Card And Terminl Block Firmware All All All All
Hardware Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block - All All All
Operating System Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block Firmware All All All All
Hardware Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock - All All All
Operating System Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware All All All All
Hardware Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block - All All All
Operating System Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block - All All All
Operating System Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware All All All All
Hardware Emerson Se4100 Simplex Ethernet I/o Card Eioc Assembly - All All All
Operating System Emerson Se4100 Simplex Ethernet I/o Card Eioc Assembly Firmware All All All All
Hardware Emerson Se4101 Simplex Ethernet I/o Card Eioc Assembly - All All All
Operating System Emerson Se4101 Simplex Ethernet I/o Card Eioc Assembly Firmware All All All All
Hardware Emerson Se4801t0x Redundant Wireless I/o Card - All All All
Operating System Emerson Se4801t0x Redundant Wireless I/o Card Firmware All All All All
Hardware Emerson Ve4103 Modbus Tcp Interface For Ethernet Connected I/o Eioc - All All All
Operating System Emerson Ve4103 Modbus Tcp Interface For Ethernet Connected I/o Eioc Firmware All All All All
Hardware Emerson Ve4104 Ethernet/ip Control Tag Integration For Ethernet Connected I/o Eioc - All All All
Operating System Emerson Ve4104 Ethernet/ip Control Tag Integration For Ethernet Connected I/o Eioc Firmware All All All All
Hardware Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o Eioc - All All All
Operating System Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o Eioc Firmware All All All All
Hardware Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o Eioc - All All All
Operating System Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o Eioc Firmware All All All All
Hardware Emerson Ve4107 Iec 61850 Mms Interface For Ethernet Connected I/o Eioc - All All All
Operating System Emerson Ve4107 Iec 61850 Mms Interface For Ethernet Connected I/o Eioc Firmware All All All All

References

ReferenceSourceLinkTags
Emerson DeltaV Distributed Control System | CISA MISC www.cisa.gov
Blog - Forescout MISC www.forescout.com
CVE Program record CVE.ORG www.cve.org canonical
NVD vulnerability detail NVD nvd.nist.gov canonical, analysis

Legacy QID Mappings

  • 591249 Emerson DeltaV Distributed Control System Multiple Vulnerabilities (ICSA-22-181-03)
© CVE.report 2026 |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report