QID 590583
Date Published: 2021-12-23
QID 590583: Emerson Ovation OCR400 Controller Multiple Vulnerabilities (ICSA-19-148-01)
AFFECTED PRODUCTS
The following versions of Emerson Ovation Controller OCR400, a process control device, are affected:
Emerson Ovation OCR400 Controller running Ovation Version 3.3.1 or earlier
These discontinued product versions include an embedded third-party FTP server, which is the vulnerable component. The vulnerable version of the FTP server was discontinued by that vendor several years ago.
QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning
Successful exploitation of these vulnerabilities may allow privilege escalation or remote code execution, or it may halt the controller.For clarification, the referenced hardware is running a software version the vendor retired in July 2015. The identified vulnerabilities exist in a third-party embedded software version discontinued by that vendor.In addition, the vulnerable services are disabled by default in all product releases since 2007.
Customers are advised to refer to CERT MITIGATIONS section ICSA-19-148-01 for affected packages and patching details.
- ICSA-19-148-01 -
www.us-cert.gov/ics/advisories/ICSA-19-148-01
CVEs related to QID 590583
| Advisory ID | Software | Component | Link |
|---|---|---|---|
| ICSA-19-148-01 |
|