First published: Thu May 20 2021(Updated: )
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The affected products utilize a weak encryption algorithm for storage of sensitive data, which may allow an attacker to more easily obtain credentials used for access.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson X-stream Enhanced Xegp Firmware | ||
Emerson X-stream Enhanced Xegp | ||
Emerson X-stream Enhanced Xegk Firmware | ||
Emerson X-stream Enhanced Xegk | ||
Emerson X-stream Enhanced Xefd Firmware | ||
Emerson X-stream Enhanced Xefd | ||
Emerson X-stream Enhanced Xexf Firmware | ||
Emerson X-stream Enhanced Xexf | ||
Emerson X-STREAM enhanced XEGP – all revisions | ||
Emerson X-STREAM enhanced XEGK – all revisions | ||
Emerson X-STREAM enhanced XEFD – all revisions | ||
Emerson X-STREAM enhanced XEXF – all revisions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27457.
The severity level of CVE-2021-27457 is high.
The affected products are Emerson Rosemount X-STREAM Gas Analyzer with specific firmware revisions.
This vulnerability allows an attacker to more easily obtain credentials used for access to the affected products.
It is recommended to contact Emerson for information on how to mitigate or fix the vulnerability.