PT-2020-2740 · Emerson · Emerson Openenterprise

Roman Lozko

·

Published

2020-05-20

·

Updated

2022-03-04

·

CVE-2020-10640

CVSS v2.0

10

Critical

VectorAV:N/AC:L/Au:N/C:C/I:C/A:C
Name of the Vulnerable Software and Affected Versions Emerson OpenEnterprise versions through 3.3.4
Description The issue is related to the incorrect implementation of the authentication mechanism in the Emerson OpenEnterprise SCADA platform for remote oil and gas applications. This may allow an attacker to execute arbitrary commands with system privileges or perform remote code execution via a specific communication service by sending a specially crafted malicious service message.
Recommendations For Emerson OpenEnterprise versions through 3.3.4, consider disabling the specific communication service that allows remote code execution until a patch is available. Restrict access to the system to minimize the risk of exploitation. At the moment, there is no information about a newer version that contains a fix for this vulnerability.

Missing Authentication

Found an issue in the description? Have something to add? Feel free to write us 👾

Weakness Enumeration

Related Identifiers

BDU:2020-02820
CVE-2020-10640

Affected Products

Emerson Openenterprise