CVE-2014-2350: Emerson DeltaV Use of Hard-coded Credentials
Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.
Affected Software
Remediation
Information
Event History
Frequently Asked Questions
What is the severity of CVE-2014-2350?
CVE-2014-2350 is classified as a high severity vulnerability due to its potential for exploitation via hardcoded credentials.
How do I fix CVE-2014-2350?
To mitigate CVE-2014-2350, it is recommended to upgrade to versions of Emerson DeltaV that do not utilize hardcoded credentials for diagnostic services.
Which versions of Emerson DeltaV are affected by CVE-2014-2350?
CVE-2014-2350 affects Emerson DeltaV versions 10.3.1, 11.3, 11.3.1, and 12.3.
What can attackers do by exploiting CVE-2014-2350?
By exploiting CVE-2014-2350, attackers can bypass intended access restrictions and gain unauthorized remote access to the system.
Is there a workaround for CVE-2014-2350 if I cannot update?
A potential workaround for CVE-2014-2350 includes restricting network access to the affected service to trusted sources only.