CVE-2022-29959: Critical severity emerson openbsi vulnerability
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29959?
CVE-2022-29959 is a vulnerability that affects Emerson OpenBSI through 2022-04-29 and mishandles credential storage.
What is Emerson OpenBSI?
Emerson OpenBSI is an engineering environment for the ControlWave and Bristol Babcock line of RTUs.
How does Emerson OpenBSI provide access control functionality?
Emerson OpenBSI provides access control functionality through user authentication and privilege management.
What versions of Emerson OpenBSI are affected by CVE-2022-29959?
Emerson OpenBSI versions up to and including 5.9, 5.9-sp1, 5.9-sp2, and 5.9-sp3 are affected by CVE-2022-29959.
What is the severity level of CVE-2022-29959?
CVE-2022-29959 has a severity level of medium with a CVSS score of 5.5.
How can I learn more about CVE-2022-29959?
You can find more information about CVE-2022-29959 on the official CISA and Forescout websites.