First published: Fri Jan 28 2022(Updated: )
Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson DeltaV | =13.3.1 | |
Emerson DeltaV | =14-feature_pack1 | |
Emerson DeltaV | =14-feature_pack2 | |
Emerson DeltaV | =14.3.1 | |
Emerson DeltaV | =r6 | |
Emerson DeltaV Distributed Control System Controllers and Workstations |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2021-44463.
The severity of CVE-2021-44463 is high with a severity value of 7.3.
CVE-2021-44463 affects all versions of the DeltaV Distributed Control System Controllers and Workstations, including versions 13.3.1, 14-feature_pack1, 14-feature_pack2, 14.3.1, and r6.
An attacker can exploit CVE-2021-44463 by replacing missing DLLs, which can allow them to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations.
As of now, there is no specific fix available for CVE-2021-44463. It is recommended to follow the guidance provided by the vendor and apply any updates or patches as they become available.