CVE-2022-2793: High severity emerson electric's proficy vulnerability
Published Aug 19, 2022
·Updated
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is vulenrable to CWE-353 Missing Support for Integrity Check, and has no authentication or authorization of data packets after establishing a connection for the SRTP protocol.
Affected Software
2 affected components
Emerson Electric\'s Proficy<=9.0.0
Emerson Proficy Machine Edition Version 9.80 and prior
Event History
Aug 19, 2022
CVE Published
via MITRE·10:33 PM
Data Sourced
via MITRE·10:33 PM
DescriptionSeverityWeakness
Frequently Asked Questions
1
What is the vulnerability ID of this security issue?
The vulnerability ID is CVE-2022-2793.
2
What software is affected by this vulnerability?
Emerson Electric's Proficy Machine Edition Version 9.00 and prior is affected.
3
What is the severity of CVE-2022-2793?
The severity of CVE-2022-2793 is high with a CVSS score of 7.8
4
What is the CWE ID of this vulnerability?
The CWE ID of this vulnerability is CWE-353.
5
Are there any known fixes or patches for this vulnerability?
Please refer to the reference link provided for more information on fixes or patches for this vulnerability.