First published: Mon Dec 26 2022(Updated: )
Emerson DeltaV Distributed Control System (DCS) has insufficient verification of firmware integrity (an inadequate checksum approach, and no signature). This affects versions before 14.3 of DeltaV M-series, DeltaV S-series, DeltaV P-series, DeltaV SIS, and DeltaV CIOC/EIOC/WIOC IO cards.
Credit: cve@mitre.org
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Emerson DeltaV Distributed Control System | <14.3 | |
Emerson DeltaV Distributed Control System | ||
All of | ||
Emerson DeltaV Distributed Control System | <14.3 | |
Emerson DeltaV Distributed Control System Sx Controller | ||
All of | ||
Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block | ||
All of | ||
Emerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware | <14.3 | |
Emerson Se4003s2b4 16-pin Mass I/o Terminal Block | ||
All of | ||
Emerson Se4003s2b524-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4003s2b524-pin Mass I/o Terminal Block | ||
All of | ||
Emerson Se4017p0 H1 I/o Interface Card And Terminl Block Firmware | <14.3 | |
Emerson Se4017p0 H1 I/o Interface Card And Terminal Block | ||
All of | ||
Emerson Se4017p1 H1 I/O Card With Integrated Power Firmware | <14.3 | |
Emerson Se4017p1 H1 I/o Card With Integrated Power | ||
All of | ||
Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware | <14.3 | |
Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock | ||
All of | ||
Emerson Se4026 Virtual I/o Module 2 Firmware | <14.3 | |
Emerson Se4026 Virtual I/o Module 2 | ||
All of | ||
Emerson Se4027 Virtual I/o Module 2 Firmware | <14.3 | |
Emerson Se4027 Virtual I/o Module 2 | ||
All of | ||
Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block | ||
All of | ||
Emerson Se4037p0 H1 I/O Interface Card and Terminal Block Firmware | <14.3 | |
Emerson Se4037p0 H1 I/O Interface Card and Terminal Block | ||
All of | ||
Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block Firmware | <14.3 | |
Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block | ||
All of | ||
Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware | <14.3 | |
Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock | ||
All of | ||
Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block | ||
All of | ||
Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block | ||
All of | ||
Emerson Se4100 Simplex Ethernet I/o Card (eioc) Assembly Firmware | <14.3 | |
Emerson Se4100 Simplex Ethernet I/o Card (eioc) Assembly | ||
All of | ||
Emerson Se4101 Simplex Ethernet I/o Card (eioc) Assembly Firmware | <14.3 | |
Emerson Se4101 Simplex Ethernet I/o Card (eioc) Assembly | ||
All of | ||
Emerson Se4801t0x Redundant Wireless I/o Card Firmware | <14.3 | |
Emerson Se4801t0x Redundant Wireless I/o Card | ||
All of | ||
Emerson Ve4103 Modbus Tcp Interface For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4103 Modbus TCP Interface for Ethernet Connected I/O (EIOC) | ||
All of | ||
Emerson Ve4104 Ethernet/IP Control Tag Integration for Ethernet Connected I/O (EIOC) Firmware | <14.3 | |
Emerson Ve4104 Ethernet/ip Control Tag Integration For Ethernet Connected I/o (eioc) | ||
All of | ||
Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o (eioc) | ||
All of | ||
Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o (eioc) | ||
All of | ||
Emerson VE4107 IEC 61850 MMS Interface for Ethernet Connected I/O (EIOC) Firmware | <14.3 | |
Emerson Ve4107 Iec 61850 Mms Interface For Ethernet Connected I/o (eioc) | ||
Emerson DeltaV Distributed Control System | <14.3 | |
Emerson DeltaV Distributed Control System | ||
Emerson DeltaV Distributed Control System | <14.3 | |
Emerson DeltaV Distributed Control System Sx Controller | ||
Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4002s1t2b6 High Side 40-pin Mass I/o Terminal Block | ||
Emerson Se4003s2b4 16-pin Mass I/O Terminal Block Firmware | <14.3 | |
Emerson Se4003s2b4 16-pin Mass I/o Terminal Block | ||
Emerson Se4003s2b524-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4003s2b524-pin Mass I/o Terminal Block | ||
Emerson Se4017p0 H1 I/o Interface Card And Terminl Block Firmware | <14.3 | |
Emerson Se4017p0 H1 I/o Interface Card And Terminal Block | ||
Emerson Se4017p1 H1 I/O Card With Integrated Power Firmware | <14.3 | |
Emerson Se4017p1 H1 I/o Card With Integrated Power | ||
Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware | <14.3 | |
Emerson Se4019p0 Simplex H1 4-port Plus Fieldbus I/o Interface With Terminalblock | ||
Emerson Se4026 Virtual I/o Module 2 Firmware | <14.3 | |
Emerson Se4026 Virtual I/o Module 2 | ||
Emerson Se4027 Virtual I/o Module 2 Firmware | <14.3 | |
Emerson Se4027 Virtual I/o Module 2 | ||
Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4032s1t2b8 High Side 40-pin Do Mass I/o Terminal Block | ||
Emerson Se4037p0 H1 I/O Interface Card and Terminal Block Firmware | <14.3 | |
Emerson Se4037p0 H1 I/O Interface Card and Terminal Block | ||
Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block Firmware | <14.3 | |
Emerson Se4037p1 Redundant H1 I/o Card With Integrated Power And Terminal Block | ||
Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock Firmware | <14.3 | |
Emerson Se4039p0 Redundant H1 4-port Plus Fieldbus I/o Interface With Terminalblock | ||
Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4052s1t2b6 High Side 40-pin Mass I/o Terminal Block | ||
Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block Firmware | <14.3 | |
Emerson Se4082s1t2b8 High Side 40-pin Do Mass I/o Terminal Block | ||
Emerson Se4100 Simplex Ethernet I/o Card (eioc) Assembly Firmware | <14.3 | |
Emerson Se4100 Simplex Ethernet I/o Card (eioc) Assembly | ||
Emerson Se4101 Simplex Ethernet I/o Card (eioc) Assembly Firmware | <14.3 | |
Emerson Se4101 Simplex Ethernet I/o Card (eioc) Assembly | ||
Emerson Se4801t0x Redundant Wireless I/o Card Firmware | <14.3 | |
Emerson Se4801t0x Redundant Wireless I/o Card | ||
Emerson Ve4103 Modbus Tcp Interface For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4103 Modbus TCP Interface for Ethernet Connected I/O (EIOC) | ||
Emerson Ve4104 Ethernet/IP Control Tag Integration for Ethernet Connected I/O (EIOC) Firmware | <14.3 | |
Emerson Ve4104 Ethernet/ip Control Tag Integration For Ethernet Connected I/o (eioc) | ||
Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4105 Ethernet/ip Interface For Ethernet Connected I/o (eioc) | ||
Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o (eioc) Firmware | <14.3 | |
Emerson Ve4106 Opc-ua Client For Ethernet Connected I/o (eioc) | ||
Emerson VE4107 IEC 61850 MMS Interface for Ethernet Connected I/O (EIOC) Firmware | <14.3 | |
Emerson Ve4107 Iec 61850 Mms Interface For Ethernet Connected I/o (eioc) |
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2022-30260 has been classified as a critical vulnerability due to insufficient verification of firmware integrity.
To mitigate CVE-2022-30260, upgrade to the latest version 14.3 or later of the affected Emerson DeltaV products.
CVE-2022-30260 affects the DeltaV M-series, S-series, P-series, SIS, and CIOC/EIOC/WIOC IO cards before version 14.3.
The potential impact of CVE-2022-30260 includes unauthorized access and manipulation of the firmware in DeltaV control systems.
Currently, the recommended workaround for CVE-2022-30260 is to ensure that the affected systems are regularly monitored and secured until an upgrade can be performed.