Home
MEDIUM: 5.1 CVSS:3.1/AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:HMEDIUM: 5.9 CVSS:4.0/AV:L/AC:H/AT:N/PR:N/UI:N/VC:N/VI:N/VA:H/SC:N/SI:N/SA:NDefault status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Description
Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.
Problem types
Product status
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Credits
Emerson reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-189-01
www.emerson.com/en-us/support/security-notifications
www.emerson.com/en-us/support/software-downloads-drivers