CVE-2021-44463: Emerson DeltaV Uncontrolled Search Path Element
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this issue?
The vulnerability ID is CVE-2021-44463.
What is the severity of CVE-2021-44463?
The severity of CVE-2021-44463 is high with a severity value of 7.3.
Which software versions are affected by CVE-2021-44463?
CVE-2021-44463 affects all versions of the DeltaV Distributed Control System Controllers and Workstations, including versions 13.3.1, 14-feature_pack1, 14-feature_pack2, 14.3.1, and r6.
How can an attacker exploit this vulnerability?
An attacker can exploit CVE-2021-44463 by replacing missing DLLs, which can allow them to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations.
Is there a fix available for CVE-2021-44463?
As of now, there is no specific fix available for CVE-2021-44463. It is recommended to follow the guidance provided by the vendor and apply any updates or patches as they become available.