First published: Thu May 22 2014(Updated: )
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 allows local users to modify or read configuration files by leveraging engineering-level privileges.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson DeltaV | =10.3.1 | |
Emerson DeltaV | =11.3 | |
Emerson DeltaV | =11.3.1 | |
Emerson DeltaV | =12.3 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The severity of CVE-2014-2349 is considered high due to the potential for unauthorized access to sensitive configuration files.
To mitigate CVE-2014-2349, ensure that access controls are properly enforced to restrict engineering-level privileges.
CVE-2014-2349 affects Emerson DeltaV versions 10.3.1, 11.3, 11.3.1, and 12.3.
CVE-2014-2349 requires local access, so remote attackers cannot directly exploit this vulnerability.
Exploiting CVE-2014-2349 could allow local users to modify or read sensitive configuration files, potentially leading to system misconfigurations.