Home
HIGH: 7.7 CVSS:3.1/AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:NHIGH: 8.5 CVSS:4.0/AV:L/AC:L/AT:N/PR:N/UI:N/VC:H/VI:H/VA:N/SC:N/SI:N/SA:NDefault status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Default status
unaffected
Any version before ValveLink 14.0
affected
Description
Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.
Problem types
Product status
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Any version before ValveLink 14.0
Credits
Emerson reported these vulnerabilities to CISA.
References
www.cisa.gov/news-events/ics-advisories/icsa-25-189-01
www.emerson.com/en-us/support/security-notifications
www.emerson.com/en-us/support/software-downloads-drivers