CVE-2022-2789: Medium severity emerson proficy machine edition vulnerability
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-2789?
CVE-2022-2789 is a vulnerability found in Emerson Electric's Proficy Machine Edition Version 9.00 and prior that is vulnerable to CWE-345 Insufficient Verification of Data Authenticity.
What is CWE-345?
CWE-345 is a Common Weakness Enumeration category that refers to Insufficient Verification of Data Authenticity vulnerability.
How does CVE-2022-2789 affect Emerson Electric's Proficy Machine Edition?
CVE-2022-2789 affects Emerson Electric's Proficy Machine Edition Version 9.00 and prior by allowing the display of logic that is different than the compiled logic.
What is the severity of CVE-2022-2789?
CVE-2022-2789 has a severity rating of 5.5, which is considered medium.
How can I fix CVE-2022-2789?
To fix CVE-2022-2789, it is recommended to update Emerson Electric's Proficy Machine Edition to version 9.00 or later.