First published: Tue Nov 22 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulnerable to CWE-434 Unrestricted Upload of File with Dangerous Type, and will upload any file written into the PLC logic folder to the connected PLC.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Proficy | <=9.00 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID for this issue is CVE-2022-2791.
The severity of CVE-2022-2791 is high with a severity value of 7.8.
Emerson Electric's Proficy Machine Edition Version 9.00 and prior are affected by CVE-2022-2791.
CVE-2022-2791 falls under CWE-434 Unrestricted Upload of File with Dangerous Type.
To fix CVE-2022-2791, update Emerson Electric's Proficy Machine Edition to a version beyond 9.00.