First published: Fri Aug 19 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-347 Improper Verification of Cryptographic Signature, and does not properly verify compiled logic (PDT files) and data blocks data (BLD/BLK files).
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Electric\'s Proficy | <=9.0.0 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-2790.
The severity of CVE-2022-2790 is medium.
The CWE ID for this vulnerability is CWE-347.
Emerson Electric's Proficy Machine Edition Version 9.00 and prior are affected by CVE-2022-2790.
To fix CVE-2022-2790, it is recommended to update to a version higher than 9.00.