First published: Fri Aug 19 2022(Updated: )
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson Electric\'s Proficy | <=9.0.0 | |
Emerson Proficy Machine Edition Version 9.80 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
The vulnerability ID is CVE-2022-2793.
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is affected.
The severity of CVE-2022-2793 is high with a CVSS score of 7.8
The CWE ID of this vulnerability is CWE-353.
Please refer to the reference link provided for more information on fixes or patches for this vulnerability.