First published: Thu Oct 03 2013(Updated: )
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier allows remote attackers to execute arbitrary code by connecting to the debug service.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
ENEA OSE | <=1.20 | |
Emerson Roc800l | ||
ENEA OSE | <=3.50 | |
Emerson Roc 800l Remote Terminal Unit | ||
ENEA OSE | <=2.30 | |
Emerson DL 8000 Remote Terminal Unit Firmware |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2013-0692 is classified as a high severity vulnerability, allowing remote code execution.
To fix CVE-2013-0692, update the affected ENEA OSE and Emerson RTUs to the latest software version.
CVE-2013-0692 affects ENEA OSE and various Emerson remote terminal units including ROC800, DL8000, and ROC800L with specific software versions.
Yes, CVE-2013-0692 can be exploited remotely due to its vulnerability in the debug service.
Attackers can execute arbitrary code on the affected devices by exploiting CVE-2013-0692.