CVE-2022-29960: Weak Encryption
Emerson OpenBSI through 2022-04-29 uses weak cryptography. It is an engineering environment for the ControlWave and Bristol Babcock line of RTUs. DES with hardcoded cryptographic keys is used for protection of certain system credentials, engineering files, and sensitive utilities.
Affected Software
Event History
Frequently Asked Questions
What is CVE-2022-29960?
CVE-2022-29960 is a vulnerability in Emerson OpenBSI through 2022-04-29 that uses weak cryptography, specifically DES with hardcoded cryptographic keys.
What software is affected by CVE-2022-29960?
Emerson OpenBSI versions up to and including 5.9, 5.9-sp1, 5.9-sp2, and 5.9-sp3 are affected by CVE-2022-29960.
What is the severity of CVE-2022-29960?
CVE-2022-29960 has a severity score of 5.5, which is considered medium.
How does CVE-2022-29960 impact the system?
CVE-2022-29960 can lead to unauthorized access and compromise of certain system credentials, engineering files, and sensitive utilities.
How can I fix CVE-2022-29960?
To fix CVE-2022-29960, it is recommended to update to a version of Emerson OpenBSI that addresses the vulnerability.