CVE-2022-30264: Critical severity emerson dl 8000 remote terminal unit firmware vulnerability
The Emerson ROC and FloBoss RTU product lines through 2022-05-02 perform insecure filesystem operations. They utilize the ROC protocol (4000/TCP, 5000/TCP) for communications between a master terminal and RTUs. Opcode 203 of this protocol allows a master terminal to transfer files to and from the flash filesystem and carrying out arbitrary file and directory read, write, and delete operations.
Affected Software
Event History
Frequently Asked Questions
What is the vulnerability ID of this vulnerability?
The vulnerability ID is CVE-2022-30264.
What is the severity of CVE-2022-30264?
The severity of CVE-2022-30264 is critical.
Which product lines are affected by CVE-2022-30264?
The Emerson ROC and FloBoss RTU product lines are affected by CVE-2022-30264.
What is the ROC protocol used for in relation to CVE-2022-30264?
The ROC protocol is used for communications between a master terminal and RTUs in relation to CVE-2022-30264.
What is the recommended mitigation for CVE-2022-30264?
Update the affected Emerson ROC and FloBoss RTU product lines to a version after 2022-05-02 to mitigate CVE-2022-30264.