First published: Tue Aug 16 2022(Updated: )
Emerson OpenBSI through 2022-04-29 mishandles credential storage. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. This environment provides access control functionality through user authentication and privilege management. The credentials for various users are stored insecurely in the SecUsers.ini file by using a simple string transformation rather than a cryptographic mechanism.
Credit: cve@mitre.org cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
Emerson OpenBSI | <5.9 | |
Emerson OpenBSI | =5.9 | |
Emerson OpenBSI | =5.9-sp1 | |
Emerson OpenBSI | =5.9-sp2 | |
Emerson OpenBSI | =5.9-sp3 | |
Emerson OpenBSI: Versions 5.9 SP3 and prior |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-29959 is a vulnerability that affects Emerson OpenBSI through 2022-04-29 and mishandles credential storage.
Emerson OpenBSI is an engineering environment for the ControlWave and Bristol Babcock line of RTUs.
Emerson OpenBSI provides access control functionality through user authentication and privilege management.
Emerson OpenBSI versions up to and including 5.9, 5.9-sp1, 5.9-sp2, and 5.9-sp3 are affected by CVE-2022-29959.
CVE-2022-29959 has a severity level of medium with a CVSS score of 5.5.
You can find more information about CVE-2022-29959 on the official CISA and Forescout websites.