Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Deltav | Emerson | 10.3.1 (including) | 10.3.1 (including) |
Deltav | Emerson | 11.3 (including) | 11.3 (including) |
Deltav | Emerson | 11.3.1 (including) | 11.3.1 (including) |
Deltav | Emerson | 12.3 (including) | 12.3 (including) |