CVE-2013-0693: Infoleak
The kernel in ENEA OSE on the Emerson Process Management ROC800 RTU with software 3.50 and earlier, DL8000 RTU with software 2.30 and earlier, and ROC800L RTU with software 1.20 and earlier performs network-beacon broadcasts, which allows remote attackers to obtain potentially sensitive information about device presence by listening for broadcast traffic.
Affected Software
Event History
Frequently Asked Questions
What is the severity of CVE-2013-0693?
CVE-2013-0693 is considered a high-severity vulnerability due to the risk of sensitive information exposure.
How do I fix CVE-2013-0693?
To fix CVE-2013-0693, upgrade the affected ENEA OSE and Emerson RTU devices to the latest software version.
What types of devices are affected by CVE-2013-0693?
CVE-2013-0693 affects ENEA OSE on various Emerson Process Management RTUs including ROC800, DL8000, and ROC800L with specified software versions.
What information can be exposed due to CVE-2013-0693?
CVE-2013-0693 may allow remote attackers to obtain potentially sensitive information via network-beacon broadcasts.
Is there a public advisory for CVE-2013-0693?
Yes, CVE-2013-0693 has a public advisory issued by ICS-CERT detailing the vulnerability and recommended actions.