QID 591138

Date Published: 2022-10-21

QID 591138: Emerson Rosemount X-STREAM Multiple Vulnerabilities (icsa-21-138-01)

AFFECTED PRODUCTS
The following versions of Emerson's Rosemount X-STREAM gas analysis software, are affected:
X-STREAM enhanced XEGP - all revisions
X-STREAM enhanced XEGK - all revisions
X-STREAM enhanced XEFD - all revisions
X-STREAM enhanced XEXF - all revisions

QID Detection Logic (Authenticated):
QID checks for the Vulnerable version of using passive scanning

Successful exploitation of these vulnerabilities could allow an attacker to obtain sensitive information, modify configuration, or affect the availability of the device.

  • CVSS V3 rated as Critical - 9.8 severity.
  • CVSS V2 rated as High - 7.5 severity.
  • Solution

    Customers are advised to refer to CERT MITIGATIONS section icsa-21-138-01 for affected packages and patching details.

    Vendor References
    Software Advisories
    Advisory ID Software Component Link