PT-2020-19319 · Emerson · Valvelink
Published
2020-03-05
·
Updated
2020-03-09
·
CVE-2020-6971
CVSS v3.1
7.8
High
| Vector | AV:L/AC:L/PR:L/UI:N/S:U/C:H/I:H/A:H |
Name of the Vulnerable Software and Affected Versions
Emerson ValveLink versions 12.0.264 through 13.4.118
Description
A vulnerability in the ValveLink software may allow a local, unprivileged, trusted insider to escalate privileges due to insecure configuration parameters.
Recommendations
For Emerson ValveLink versions 12.0.264 through 13.4.118, consider reconfiguring the software to secure configuration parameters until a patch is available.
As a temporary workaround, restrict access to the ValveLink software to minimize the risk of exploitation.
Fix
Improper Access Control
Improper Privilege Management
Found an issue in the description? Have something to add? Feel free to write us 👾
Related Identifiers
Affected Products
Valvelink