CVE-2021-26264: Emerson DeltaV Missing Authentication for Critical Function
Published Jan 28, 2022
·Updated
A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.
Affected Software
3 affected components
Emerson DeltaV Distributed Control System Controllers and Workstations
Emerson DeltaV Workstation
Emerson DeltaV Distributed Control System
Event History
Jan 28, 2022
CVE Published
via MITRE·07:09 PM
Data Sourced
via MITRE·07:09 PM
DescriptionSeverity
Data Sourced
via NVD·08:15 PM
DescriptionSeverityWeaknessAffected Software
Frequently Asked Questions
1
What is the vulnerability ID for this issue?
The vulnerability ID for this issue is CVE-2021-26264.
2
What is the severity of CVE-2021-26264?
The severity of CVE-2021-26264 is medium (5.5).
3
Which software versions are affected by CVE-2021-26264?
All versions of Emerson Deltav Workstation and Emerson DeltaV Distributed Control System are affected by CVE-2021-26264.
4
What is the impact of CVE-2021-26264?
A specially crafted script could cause the DeltaV Distributed Control System Controllers to restart and cause a denial-of-service condition.
5
Is there a fix available for CVE-2021-26264?
The vendor may release a patch or mitigation to address CVE-2021-26264. Please refer to the vendor's advisory for more information.