CVE Vulnerabilities

CVE-2014-2350

Published: May 22, 2014 | Modified: May 23, 2014
CVSS 3.x
N/A
Source:
NVD
CVSS 2.x
7.5 HIGH
AV:N/AC:L/Au:N/C:P/I:P/A:P
RedHat/V2
RedHat/V3
Ubuntu

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

Affected Software

Name Vendor Start Version End Version
Deltav Emerson 10.3.1 (including) 10.3.1 (including)
Deltav Emerson 11.3 (including) 11.3 (including)
Deltav Emerson 11.3.1 (including) 11.3.1 (including)
Deltav Emerson 12.3 (including) 12.3 (including)

References