First published: Fri Aug 19 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-284 Improper Access Control, and stores project data in a directory with improper access control lists.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Electric\'s Proficy | <=9.0.0 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-2792 is a vulnerability in Emerson Electric's Proficy Machine Edition Version 9.00 and prior that is vulnerable to CWE-284 Improper Access Control.
Vulnerability CVE-2022-2792 has a severity rating of 7.5 out of 10, which is considered high.
CWE-284 refers to the Common Weakness Enumeration category for Improper Access Control.
Emerson Electric's Proficy Machine Edition Version 9.00 and prior are affected by vulnerability CVE-2022-2792.
You can find more information about vulnerability CVE-2022-2792 at the following reference link: [https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-06](https://www.cisa.gov/uscert/ics/advisories/icsa-22-228-06)