First published: Thu Sep 27 2018(Updated: )
Emerson AMS Device Manager v12.0 to v13.5. A specially crafted script may be run that allows arbitrary remote code execution.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson AMS Device Manager | >=12.0<=13.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2018-14804 has been rated with a critical severity level due to its potential for arbitrary remote code execution.
To fix CVE-2018-14804, users should update Emerson AMS Device Manager to a patched version beyond 13.5.
CVE-2018-14804 affects Emerson AMS Device Manager versions from 12.0 to 13.5.
CVE-2018-14804 is classified as a remote code execution vulnerability.
Yes, CVE-2018-14804 can be exploited remotely by executing specially crafted scripts.