First published: Thu May 20 2021(Updated: )
A vulnerability has been found in multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer. The webserver of the affected products allows unvalidated files to be uploaded, which an attacker could utilize to execute arbitrary code.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson X-stream Enhanced Xegp Firmware | ||
Emerson X-stream Enhanced Xegp | ||
Emerson X-stream Enhanced Xegk Firmware | ||
Emerson X-stream Enhanced Xegk | ||
Emerson X-stream Enhanced Xefd Firmware | ||
Emerson X-stream Enhanced Xefd | ||
Emerson X-stream Enhanced Xexf Firmware | ||
Emerson X-stream Enhanced Xexf | ||
Emerson X-STREAM enhanced XEGP – all revisions | ||
Emerson X-STREAM enhanced XEGK – all revisions | ||
Emerson X-STREAM enhanced XEFD – all revisions | ||
Emerson X-STREAM enhanced XEXF – all revisions |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this vulnerability is CVE-2021-27459.
Multiple revisions of Emerson Rosemount X-STREAM Gas Analyzer are affected by this vulnerability.
The severity of CVE-2021-27459 is critical with a CVSS score of 9.8.
An attacker can exploit this vulnerability by uploading unvalidated files to the webserver of the affected products, allowing them to execute arbitrary code.
Please refer to the vendor's advisory or security bulletin for information on available fixes or patches for this vulnerability.