CVE-2020-6971: High severity Emerson ValveLink vulnerability
In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2020-6971?
CVE-2020-6971 is a vulnerability in Emerson ValveLink software that allows a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.
Which versions of Emerson ValveLink are affected by CVE-2020-6971?
Emerson ValveLink versions 12.0.264 to 13.4.118 are affected by CVE-2020-6971.
What is the severity of CVE-2020-6971?
CVE-2020-6971 has a severity rating of 7.8 (high).
How can the escalation of privileges be exploited in CVE-2020-6971?
The escalation of privileges in CVE-2020-6971 can be exploited by a local, unprivileged, trusted insider due to insecure configuration parameters.
Is there a fix available for CVE-2020-6971?
A fix for CVE-2020-6971 may be available from Emerson. It is recommended to contact Emerson for further information and mitigation steps.