Known Vulnerabilities for products from Emerson

Listed below are 20 of the newest known vulnerabilities associated with the vendor "Emerson".

These CVEs are retrieved based on exact matches on listed vendor information (CPE data) as well as a keyword search to ensure the newest vulnerabilities with no officially listed vendor information are still displayed.

Data on known vulnerable products is also displayed based on information from known CPEs, each product links to its respective vulnerability page.

Additional devices specifications by Emerson can be found at device.report : Emerson

Known Vulnerabilities

CVE Shortened Description Severity Publish Date Last Modified
CVE-2021-42542 The affected product is vulnerable to directory traversal due to mishandling of provided backup folder structure. 8.8 - HIGH 2021-10-22 2021-10-27
CVE-2021-42540 The affected product is vulnerable to a unsanitized extract folder for system configuration. A low-privileged user can levera... 8.8 - HIGH 2021-10-22 2021-10-28
CVE-2021-42539 The affected product is vulnerable to a missing permission validation on system backup restore, which could lead to account t... 8.8 - HIGH 2021-10-22 2021-10-27
CVE-2021-42538 The affected product is vulnerable to a parameter injection via passphrase, which enables the attacker to supply uncontrolled... 8.8 - HIGH 2021-10-22 2022-07-25
CVE-2021-42536 The affected product is vulnerable to a disclosure of peer username and password by allowing all users access to read global ... 6.5 - MEDIUM 2021-10-22 2021-10-27
CVE-2021-38485 The affected product is vulnerable to improper input validation in the restore file. This enables an attacker to provide mali... 8.8 - HIGH 2021-10-22 2021-10-27
CVE-2021-29298 Improper Input Validation in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of servi... 5.3 - MEDIUM 2021-07-30 2021-08-09
CVE-2021-29297 Buffer Overflow in Emerson GE Automation Proficy Machine Edition v8.0 allows an attacker to cause a denial of service and app... 5.3 - MEDIUM 2021-07-30 2021-08-09
CVE-2021-27467 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected product’s web... 6.1 - MEDIUM 2021-05-20 2021-05-28
CVE-2021-27465 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications do... 6.1 - MEDIUM 2021-05-20 2021-05-28
CVE-2021-27463 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected applications ut... 5.3 - MEDIUM 2021-05-20 2021-05-28
CVE-2021-27461 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected webserver appli... 7.5 - HIGH 2021-05-20 2021-05-28
CVE-2021-27459 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affecte... 9.8 - CRITICAL 2021-05-20 2021-05-28
CVE-2021-27457 A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utiliz... 7.5 - HIGH 2021-05-20 2022-07-30
CVE-2021-26264 A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause ... 5.5 - MEDIUM 2022-01-28 2022-02-02
CVE-2020-27254 Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are ... 7.5 - HIGH 2020-12-21 2020-12-22
CVE-2020-19419 Incorrect Access Control in Emerson Smart Wireless Gateway 1420 4.6.59 allows remote attackers to obtain sensitive device inf... 7.5 - HIGH 2021-03-10 2022-10-05
CVE-2020-19417 Emerson Smart Wireless Gateway 1420 4.6.59 allows non-privileged users (such as the default account 'maint') to perform admin... 8.8 - HIGH 2021-03-10 2022-07-12
CVE-2020-16235 ** RESERVED ** This candidate has been reserved by an organization or individual that will use it when announcing a new secur... 6.5 - MEDIUM 2022-05-19 2022-05-31
CVE-2020-12525 M&M Software fdtCONTAINER Component in versions below 3.5.20304.x and between 3.6 and 3.6.20304.x is vulnerable to deserializ... 7.8 - HIGH 2021-01-22 2022-02-10

Known software with vulnerabilities from Emerson

Type Vendor Product Version
ApplicationEmersonAms Device Manager1.0
ApplicationEmersonAperture Web Application Server4.0
ApplicationEmersonAperture Web Services Server4.0
HardwareEmersonAvocent Dsr1021-
HardwareEmersonAvocent Dsr1031-
HardwareEmersonAvocent Mpu108edac-
HardwareEmersonAvocent Mpu4032-
ApplicationEmersonDeltav9.3.1
ApplicationEmersonDeltav Proessentials Scientific Graph5.0.0.6
ApplicationEmersonDeltav Workstation9.3.1
HardwareEmersonDl 8000 Remote Terminal Unit-
HardwareEmersonGxt4-2000rt120-
HardwareEmersonNetwork Power Avocent Mergepoint Unity 2016-
Operating
System
EmersonNetwork Power Avocent Mergepoint Unity 2016 Firmware1.9.16473
ApplicationEmersonOpenenterprise Scada Server2.8.3
HardwareEmersonRoc 800 Remote Terminal Unit-
HardwareEmersonRoc 800l Remote Terminal Unit-
HardwareEmersonRx3i Cpe100-
Operating
System
EmersonRx3i Cpe100 Firmware-
HardwareEmersonRx3i Cpe115-

Popular searches for "Emerson"

Ralph Waldo Emerson

Ralph Waldo Emerson Ralph Waldo Emerson, who went by his middle name Waldo, was an American essayist, lecturer, philosopher, abolitionist and poet who led the transcendentalist movement of the mid-19th century. He was seen as a champion of individualism and a prescient critic of the countervailing pressures of society, and he disseminated his thoughts through dozens of published essays and more than 1,500 public lectures across the United States. Wikipedia

© CVE.report 2023 Twitter Nitter Twitter Viewer |

Use of this information constitutes acceptance for use in an AS IS condition. There are NO warranties, implied or otherwise, with regard to this information or its use. Any use of this information is at the user's risk. It is the responsibility of user to evaluate the accuracy, completeness or usefulness of any information, opinion, advice or other content. EACH USER WILL BE SOLELY RESPONSIBLE FOR ANY consequences of his or her direct or indirect use of this web site. ALL WARRANTIES OF ANY KIND ARE EXPRESSLY DISCLAIMED. This site will NOT BE LIABLE FOR ANY DIRECT, INDIRECT or any other kind of loss.

CVE, CWE, and OVAL are registred trademarks of The MITRE Corporation and the authoritative source of CVE content is MITRE's CVE web site. This site includes MITRE data granted under the following license.

CVE.report and Source URL Uptime Status status.cve.report