First published: Fri Aug 19 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-345 Insufficient Verification of Data Authenticity, and can display logic that is different than the compiled logic.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Electric\'s Proficy | <=9.0.0 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2789 is a vulnerability found in Emerson Electric's Proficy Machine Edition Version 9.00 and prior that is vulnerable to CWE-345 Insufficient Verification of Data Authenticity.
CWE-345 is a Common Weakness Enumeration category that refers to Insufficient Verification of Data Authenticity vulnerability.
CVE-2022-2789 affects Emerson Electric's Proficy Machine Edition Version 9.00 and prior by allowing the display of logic that is different than the compiled logic.
CVE-2022-2789 has a severity rating of 5.5, which is considered medium.
To fix CVE-2022-2789, it is recommended to update Emerson Electric's Proficy Machine Edition to version 9.00 or later.