CVE-2014-2349: Emerson DeltaV Use of Improper Authorization
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 allows local users to modify or read configuration files by leveraging engineering-level privileges.
Other sources
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.
— MITRE
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2349?
The severity of CVE-2014-2349 is considered high due to the potential for unauthorized access to sensitive configuration files.
How do I fix CVE-2014-2349?
To mitigate CVE-2014-2349, ensure that access controls are properly enforced to restrict engineering-level privileges.
What versions of Emerson DeltaV are affected by CVE-2014-2349?
CVE-2014-2349 affects Emerson DeltaV versions 10.3.1, 11.3, 11.3.1, and 12.3.
Can remote attackers exploit CVE-2014-2349?
CVE-2014-2349 requires local access, so remote attackers cannot directly exploit this vulnerability.
What is the impact of exploiting CVE-2014-2349?
Exploiting CVE-2014-2349 could allow local users to modify or read sensitive configuration files, potentially leading to system misconfigurations.