First published: Mon Dec 21 2020(Updated: )
Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF – all revisions, The affected products are vulnerable to improper authentication for accessing log and backup data, which could allow an attacker with a specially crafted URL to obtain access to sensitive information.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson X-stream Enhanced Xegp Firmware | ||
Emerson X-stream Enhanced Xegp | ||
Emerson X-stream Enhanced Xegk Firmware | ||
Emerson X-stream Enhanced Xegk | ||
Emerson X-stream Enhanced Xefd Firmware | ||
Emerson X-stream Enhanced Xefd | ||
Emerson X-stream Enhanced Xexf Firmware | ||
Emerson X-stream Enhanced Xexf | ||
Emerson X-STREAM enhanced XEGP – all revisions | ||
Emerson X-STREAM enhanced XEGK – all revisions | ||
Emerson X-STREAM enhanced XEFD – all revisions | ||
Emerson X-STREAM enhanced XEXF – all revisions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2020-27254 is a vulnerability in Emerson Rosemount X-STREAM Gas AnalyzerX-STREAM enhanced XEGP, XEGK, XEFD, XEXF that allows unauthorized access to log and backup data.
CVE-2020-27254 allows an attacker to obtain access to sensitive information by exploiting improper authentication for accessing log and backup data.
The severity of CVE-2020-27254 is high, with a CVSS score of 7.5.
To fix CVE-2020-27254, Emerson recommends updating to the latest firmware version for the affected products.
You can find more information about CVE-2020-27254 on the official website of the United States Computer Emergency Readiness Team (US-CERT).