Where
-Infinity
0

Vendor Risk Score

See how emerson compares to other vendors in security performance

View Risk Score →

Software

emerson deltav
15
emerson x-stream enhanced xefd
9
emerson x-stream enhanced xegk firmware
9
emerson x-stream enhanced xegp
9
emerson x-stream enhanced xexf firmware
9
emerson deltav distributed control system
8
emerson wireless 1420 gateway firmware
8
emerson wirelesshart 1410 gateway
8
emerson proficy machine edition
7
emerson wireless 1410 gateway
7
emerson wireless 1410 gateway firmware
7
emerson wireless 1410d gateway
7
emerson wirelesshart 1420 gateway
7
emerson x-stream enhanced xegk
7
emerson x-stream enhanced xexf
7
emerson deltav workstation
6
emerson openenterprise
6
emerson deltav distributed control system sq controller firmware
5
emerson deltav distributed control system sx controller firmware
5
emerson deltav proessentials scientific graph
5
emerson dl 8000 remote terminal unit firmware
5
emerson electric's proficy
5
emerson roc 800l remote terminal unit
5
emerson se4002s1t2b6 high side 40-pin mass i/o terminal block
5
emerson se4002s1t2b6 high side 40-pin mass i/o terminal block firmware
5
emerson se4003s2b4 16-pin mass i/o terminal block
5
emerson se4003s2b4 16-pin mass i/o terminal block firmware
5
emerson se4003s2b524-pin mass i/o terminal block
5
emerson se4003s2b524-pin mass i/o terminal block firmware
5
emerson se4017p0 h1 i/o interface card and terminal block
5
emerson se4017p0 h1 i/o interface card and terminl block firmware
5
emerson se4017p1 h1 i/o card with integrated power
5
emerson se4017p1 h1 i/o card with integrated power firmware
5
emerson se4019p0 simplex h1 4-port plus fieldbus i/o interface with terminalblock
5
emerson se4019p0 simplex h1 4-port plus fieldbus i/o interface with terminalblock firmware
5
emerson se4026 virtual i/o module 2
5
emerson se4026 virtual i/o module 2 firmware
5
emerson se4027 virtual i/o module 2
5
emerson se4027 virtual i/o module 2 firmware
5
emerson se4032s1t2b8 high side 40-pin do mass i/o terminal block
5
emerson se4032s1t2b8 high side 40-pin do mass i/o terminal block firmware
5
emerson se4037p0 h1 i/o interface card and terminal block
5
emerson se4037p0 h1 i/o interface card and terminal block firmware
5
emerson se4037p1 redundant h1 i/o card with integrated power and terminal block
5
emerson se4037p1 redundant h1 i/o card with integrated power and terminal block firmware
5
emerson se4039p0 redundant h1 4-port plus fieldbus i/o interface with terminalblock
5
emerson se4039p0 redundant h1 4-port plus fieldbus i/o interface with terminalblock firmware
5
emerson se4052s1t2b6 high side 40-pin mass i/o terminal block
5
emerson se4052s1t2b6 high side 40-pin mass i/o terminal block firmware
5
emerson se4082s1t2b8 high side 40-pin do mass i/o terminal block
5
Severity
7.5
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

UNSUPPORTED WHEN ASSIGNED Emerson Dixell XWEB-500 products are affected by information disclosure via directory listing. A potential attacker can use this misconfiguration to access all the files in the remote directories. Note: the product has not been supported since 2018 and should be removed or replaced.

1 / 2
First published (updated )
Severity
9.8
Infoleak
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

UNSUPPORTED WHEN ASSIGNED Emerson Dixell XWEB-500 products are affected by arbitrary file write vulnerability in /cgi-bin/logoextraupload.cgi, /cgi-bin/calsave.cgi, and /cgi-bin/loutils.cgi. An attacker will be able to write any file on the target system without any kind of authentication mechanism, and this can lead to denial of service and potentially remote code execution. Note: the product has not been supported since 2018 and should be removed or replaced.

1 / 2
First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Incorrect permissions in the installation directories for shared SystemLink Elixir based services may allow an authenticated user to potentially enable escalation of privilege via local access.

First published (updated )
Severity
7.8
AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

Incorrect directory permissions for the shared NI RabbitMQ service may allow a local authenticated user to read RabbitMQ configuration information and potentially enable escalation of privileges.

First published (updated )
Severity
9.8
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

A Heap-based Buffer Overflow was found in Emerson OpenEnterprise SCADA Server 2.83 (if Modbus or ROC Interfaces have been installed and are in use) and all versions of OpenEnterprise 3.1 through 3.3.3, where a specially crafted script could execute code on the OpenEnterprise Server.

First published (updated )
Severity
7.8
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H

In Emerson ValveLink v12.0.264 to v13.4.118, a vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.

First published (updated )
Severity
7.5
Buffer Overflow
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:N/A:H

A Stack-based Buffer Overflow issue was discovered in Emerson Process Management ControlWave Micro Process Automation Controller: ControlWave Micro [ProConOS v.4.01.280] firmware: CWM v.05.78.00 and prior. A stack-based buffer overflow vulnerability caused by sending crafted packets on Port 20547 could force the PLC to change its state into halt mode.

First published (updated )
Severity
5.9
Input Validation
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:H/A:N

Emerson ValveLink products receive input or data, but does not validate or incorrectly validates that the input has the properties that are required to process the data safely and correctly.

Remedy

Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
First published (updated )
Severity
6.8
CVSS:3.0/AV:A/AC:H/PR:H/UI:N/S:C/C:H/I:L/A:L

An issue was discovered in Emerson DeltaV Easy Security Management DeltaV V12.3, DeltaV V12.3.1, and DeltaV V13.3. Critical vulnerabilities may allow a local attacker to elevate privileges within the DeltaV control system.

First published (updated )
Severity
5.4
CVSS:3.0/AV:A/AC:H/PR:N/UI:N/S:U/C:L/I:L/A:L

An issue was discovered in Emerson SE4801T0X Redundant Wireless I/O Card V13.3, and SE4801T1X Simplex Wireless I/O Card V13.3. DeltaV Wireless I/O Cards (WIOC) running the firmware available in the DeltaV system, release v13.3, have the SSH (Secure Shell) functionality enabled unnecessarily.

First published (updated )
Severity
9.8
XEE
CVSS:3.0/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

An XML External Entity (XXE) issue was discovered in Emerson Liebert SiteScan Web Version 6.5, and prior. An attacker may enter malicious input to Liebert SiteScan through a weakly configured XML parser causing the application to execute arbitrary code or disclose file contents from a server or connected network.

First published (updated )
Severity
7.5
AV:N/AC:L/Au:N/C:P/I:P/A:P

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 uses hardcoded credentials for diagnostic services, which allows remote attackers to bypass intended access restrictions via a TCP session, as demonstrated by a session that uses the telnet program.

Remedy

Emerson has created a patch to mitigate these vulnerabilities. Emerson has distributed a notification (KBA NK-1400-0031) that provides details of the vulnerabilities, recommended mitigations, and instructions on obtaining and installing the patch. This document is available on Emerson’s support site to users who have support contracts with Emerson. If you do not have access to this site and need to apply the patch, please contact customer service at 1‑800‑833‑8314.
First published (updated )
Severity
6.2
AV:L/AC:L/Au:N/C:P/I:P/A:P

Emerson DeltaV 10.3.1, 11.3, 11.3.1, and 12.3 allows local users to modify or read configuration files by leveraging engineering-level privileges.

1 / 2

Remedy

Emerson has created a patch to mitigate these vulnerabilities. Emerson has distributed a notification (KBA NK-1400-0031) that provides details of the vulnerabilities, recommended mitigations, and instructions on obtaining and installing the patch. This document is available on Emerson’s support site to users who have support contracts with Emerson. If you do not have access to this site and need to apply the patch, please contact customer service at 1‑800‑833‑8314.
First published (updated )
Severity
8.5
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Emerson PAC Machine Edition 9.80 contains an unquoted service path vulnerability in the TrapiServer service that allows local users to potentially execute code with elevated privileges. Attackers can exploit the unquoted path in the service configuration to inject malicious code that would execute with LocalSystem permissions during service startup.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Emerson Movicon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-3871.

First published (updated )

This vulnerability allows remote attackers to execute arbitrary code on affected installations of Emerson Movicon. User interaction is required to exploit this vulnerability in that the target must visit a malicious page or open a malicious file. The ZDI has assigned a CVSS rating of 7.8. The following CVEs are assigned: CVE-2024-3871.

First published (updated )
Advisory
ZDI-25-1037
Severity
9.4
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:L

Emerson ValveLink Products store sensitive information in cleartext in memory. The sensitive memory might be saved to disk, stored in a core dump, or remain uncleared if the product crashes, or if the programmer does not properly clear the memory before freeing it.

Remedy

Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
First published (updated )
Severity
5.9
AV:L/AC:H/PR:N/UI:N/S:U/C:N/I:N/A:H

Emerson ValveLink products use a fixed or controlled search path to find resources, but one or more locations in that path can be under the control of unintended actors.

Remedy

Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
First published (updated )
Severity
8.5
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Emerson ValveLink products do not use or incorrectly uses a protection mechanism that provides sufficient defense against directed attacks against the product.

Remedy

Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
First published (updated )
Severity
8.5
AV:L/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:N

Emerson ValveLink Products store sensitive information in cleartext within a resource that might be accessible to another control sphere.

Remedy

Emerson recommends users update their Valvelink software to ValveLink 14.0 or later. The upgrade can be downloaded from the Emerson website https://www.emerson.com/en-us/support/software-downloads-drivers  .For more information see the associated Emerson security notification. https://www.emerson.com/en-us/support/security-notifications
First published (updated )
Severity
9.8
Command Injection
AV:A/AC:H/PR:N/UI:N/S:C/C:N/I:L/A:H

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an authenticated user with network access could run arbitrary commands from a remote computer.

Remedy

Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications  web page.
First published (updated )
Severity
9.8
Command Injection
AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could execute arbitrary commands in root context from a remote computer.

Remedy

Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications  web page.
First published (updated )
Severity
8.3
CVSS:3.1/AV:N/AC:H/PR:N/UI:N/S:U/C:H/I:H/A:H

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could bypass authentication and acquire admin capabilities.

Remedy

Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications  web page.
First published (updated )
Severity
9.1
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:H

In Emerson Rosemount GC370XA, GC700XA, and GC1500XA products, an unauthenticated user with network access could obtain access to sensitive information or cause a denial-of-service condition.

Remedy

Emerson recommends end users update the affected products' firmware. For update information, contact Emerson Security https://www.emerson.com/en-us/support/security-notifications  web page.
First published (updated )
Severity
8.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:R/S:U/C:H/I:H/A:H

Missing DLLs, if replaced by an insider, could allow an attacker to achieve local privilege escalation on the DeltaV Distributed Control System Controllers and Workstations (All versions) when some DeltaV services are started.

First published (updated )
Severity
6.1
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:U/C:N/I:N/A:H

A specially crafted script could cause the DeltaV Distributed Control System Controllers (All Versions) to restart and cause a denial-of-service condition.

First published (updated )
Severity
8.8
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:N/I:L/A:N

Inadequate folder security permissions in Emerson OpenEnterprise versions through 3.3.4 may allow modification of important configuration files, which could cause the system to fail or behave in an unpredictable manner.

Remedy

Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 5 (3.3.5), to resolve these issues. OpenEnterprise Service Packs are available to users with access to the Emerson SupportNet system (login required). Details will be found in the downloads area. Please send any questions via a SupportNet ticket or by contacting Emerson at US 800-537-9313. For users outside of the United States, please use international toll-free numbers.
First published (updated )
Severity
10
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:H/A:H

Emerson OpenEnterprise versions through 3.3.4 may allow an attacker to run an arbitrary commands with system privileges or perform remote code execution via a specific communication service.

Remedy

Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 5 (3.3.5), to resolve these issues. OpenEnterprise Service Packs are available to users with access to the Emerson SupportNet system (login required). Details will be found in the downloads area. Please send any questions via a SupportNet ticket or by contacting Emerson at US 800-537-9313. For users outside of the United States, please use international toll-free numbers.
First published (updated )
Severity
7.5
Weak Encryption
CVSS:3.1/AV:N/AC:L/PR:N/UI:N/S:U/C:H/I:N/A:N

Inadequate encryption may allow the passwords for Emerson OpenEnterprise versions through 3.3.4 user accounts to be obtained.

Remedy

Emerson recommends all users upgrade to OpenEnterprise 3.3, Service Pack 5 (3.3.5), to resolve these issues. OpenEnterprise Service Packs are available to users with access to the Emerson SupportNet system (login required). Details will be found in the downloads area. Please send any questions via a SupportNet ticket or by contacting Emerson at US 800-537-9313. For users outside of the United States, please use international toll-free numbers.
First published (updated )
Severity
6.5
Weak Encryption
CVSS:3.1/AV:L/AC:L/PR:L/UI:N/S:C/C:H/I:N/A:N

Inadequate encryption may allow the credentials used by Emerson OpenEnterprise, up through version 3.3.5, to access field devices and external systems to be obtained.

First published (updated )

Contact

SecAlerts Pty Ltd.
132 Wickham Terrace
Fortitude Valley,
QLD 4006, Australia
info@secalerts.co
By using SecAlerts services, you agree to our services end-user license agreement. This website is safeguarded by reCAPTCHA and governed by the Google Privacy Policy and Terms of Service. All names, logos, and brands of products are owned by their respective owners, and any usage of these names, logos, and brands for identification purposes only does not imply endorsement. If you possess any content that requires removal, please get in touch with us.
© 2026 SecAlerts Pty Ltd.
ABN: 70 645 966 203, ACN: 645 966 203