First published: Fri Feb 09 2024(Updated: )
In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.
Credit: ics-cert@hq.dhs.gov
Affected Software | Affected Version | How to fix |
---|---|---|
All of | ||
Emerson Gc370xa Firmware | =4.1.5 | |
Emerson Gc370xa | ||
All of | ||
Emerson GC700XA | =4.1.5 | |
Emerson GC700XA | ||
All of | ||
Emerson Gc1500xa Firmware | =4.1.5 | |
Emerson GC1500XA |
Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications web page.
Sign up to SecAlerts for real-time vulnerability data matched to your software, aggregated from hundreds of sources.
CVE-2023-49716 is considered a critical vulnerability due to the ability of an authenticated user to execute arbitrary commands remotely.
To mitigate CVE-2023-49716, update the affected Emerson Rosemount products to the latest firmware version provided by Emerson.
The affected products include Emerson Rosemount GC370XA, GC700XA, and GC1500XA with firmware version 4.1.5.
CVE-2023-49716 can be exploited by authenticated users with network access to the affected Emerson products.
The potential impacts include unauthorized command execution, which can lead to system compromise or disruption of services.