CVE Vulnerabilities

CVE-2022-29959

Insufficiently Protected Credentials

Published: Aug 16, 2022 | Modified: Feb 13, 2024
CVSS 3.x
5.5
MEDIUM
Source:
NVD
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:N/A:N
CVSS 2.x
RedHat/V2
RedHat/V3
Ubuntu

Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.

Weakness

The product transmits or stores authentication credentials, but it uses an insecure method that is susceptible to unauthorized interception and/or retrieval.

Affected Software

Name Vendor Start Version End Version
Openbsi Emerson * 5.9 (excluding)
Openbsi Emerson 5.9 (including) 5.9 (including)
Openbsi Emerson 5.9-sp1 (including) 5.9-sp1 (including)
Openbsi Emerson 5.9-sp2 (including) 5.9-sp2 (including)
Openbsi Emerson 5.9-sp3 (including) 5.9-sp3 (including)

Potential Mitigations

References