First published: Fri Feb 09 2024(Updated: )
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Emerson Gc370xa Firmware | =4.1.5 | |
Emerson Gc370xa | ||
All of | ||
Emerson GC700XA | =4.1.5 | |
Emerson GC700XA | ||
All of | ||
Emerson Gc1500xa Firmware | =4.1.5 | |
Emerson GC1500XA |
Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications web page.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-46687 is rated as critical because it allows unauthenticated remote command execution on affected Emerson products.
To mitigate CVE-2023-46687, users should update the affected Emerson Rosemount GC370XA, GC700XA, and GC1500XA products to the latest firmware version.
CVE-2023-46687 affects Emerson Rosemount GC370XA, GC700XA, and GC1500XA products running firmware version 4.1.5.
Yes, CVE-2023-46687 can be exploited remotely by an unauthenticated user with network access.
CVE-2023-46687 is a remote command execution vulnerability that can lead to unauthorized access and control over the affected devices.