Emerson Electrics Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.
The product uses a transmission protocol that does not include a mechanism for verifying the integrity of the data during transmission, such as a checksum.
Name | Vendor | Start Version | End Version |
---|---|---|---|
Electric’s_proficy | Emerson | * | 9.0.0 (including) |