First published: Thu May 19 2022(Updated: )
Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson OpenEnterprise SCADA Server | <=3.3.5 | |
Emerson OpenEnterprise All versions through 3.3.5 |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-16235 is a vulnerability in Emerson OpenEnterprise up to version 3.3.5 that allows unauthorized access to field devices and external systems by obtaining credentials through inadequate encryption.
CVE-2020-16235 affects Emerson OpenEnterprise up to version 3.3.5 by allowing unauthorized access to field devices and external systems.
CVE-2020-16235 has a severity rating of medium with a CVSS score of 6.5.
To fix CVE-2020-16235, it is recommended to update Emerson OpenEnterprise to a version beyond 3.3.5 that addresses the inadequate encryption vulnerability.
More information about CVE-2020-16235 can be found in the advisory published by the US Computer Emergency Readiness Team (US-CERT) at https://www.cisa.gov/uscert/ics/advisories/icsa-20-238-02.